Authorities often outsource the delivery and/or operation of transport services. While operations can be outsourced, organisational risks cannot. While authorities can rely on the cyber security capabilities of third parties, ultimate responsibility for security remains with the authority. An authority that does not build its security posture may face outcomes ranging from unexpected costs to disruption in the community to, in the most extreme cases, charges of criminal negligence.

Industry Lessons

A major UK train operator recently procured digital railway systems without organisational awareness of cyber security and under the assumption that cyber security was the responsibility of the system vendor. Cyber security concerns were later identified after the system went into operation. The vendor cited lack of security considerations in the procurement process and declined to take responsibility for the issue. The train operator was thus faced with significant security risks that were previously unknown and high costs to identify and implement appropriate mitigations.

Before planning and procuring smart streets systems, an authority should ensure the organisation is prepared to identify and manage operational cyber security risks.

It is likely that your organisation already has policies and processes in place to manage more general IT security risk. Many local transport authorities have implemented the NCSC’s Cyber Essentials scheme, and more mature authorities may have implemented the IT security standard ISO 27001. These standards are suited for managing general enterprise IT security, but this does not automatically mean your organisation is prepared to handle cyber security risks posed by operational technology. The guidance in this section will help ensure you have a cyber security management system (CSMS) fit for this purpose.

Smart streets have most of the same characteristics as those systems deemed as critical national infrastructure by the UK Government. Thus, the NCSC Cyber Assessment Framework (CAF) is a useful tool to gauge your local authority’s smart street programme security posture.

Authority Supported Services

Even where a local transport authority will not be managing services themselves, the authority should still build sufficient security maturity to understand wider security risks posed to transport services within their community and, where necessary, ensure appropriate assurance and management of third-party service providers.

 Applicable to:  All use cases
NCSC Connected Places CS Principles:
#3 Understanding cyber security governance and skills
Bridging the IT Security – OT Security Gap

Most authorities have an IT security team. This team is typically part of the IT department, and they usually run an information security management system (ISMS) based on ISO 27001 or otherwise implement the NCSC’s Cyber Essentials scheme, a lightweight derivative of ISO 27001. This team is responsible for the security of information and data across the authority’s enterprise estate. The IT security team will usually have responsibility for the authority’s compliance with data protection regulations, but this responsibility may be split with the legal compliance team.

Good IT security governance is essential to supporting secure smart streets. However, issues can arise from the fact that smart streets systems do not always receive appropriate oversight from the IT security team. Reasons for this vary. One reason is that many smart streets systems have traditionally been operated physically and logically separate from the authority’s enterprise IT. Another reason is that IT security standards like ISO 27001 have insufficient considerations for OT systems and the engineering lifecycles through which they are managed.

Many local authorities have identified that smart streets projects do not receive appropriate cyber security risk management and governance. It also acknowledged that it would be difficult to leave these responsibilities entirely to smart streets engineers, particularly given some projects lack an engineering layer on the authority side altogether.

What is needed in authorities is greater and more structured collaboration between smart streets project staff and the IT security team to ensure that cyber security risk is properly managed for all smart streets projects. IT security and smart streets stakeholders should collaborate to form an initiative that looks at existing security governance and considers whether it is fit for purpose. This section provides guidance around what effective security governance for connected places looks like.

Formally Establishing a Cyber Security Management System

IEC 62443-2-1 is a standard intended to supplement ISO 27001 by extending the ISMS with a CSMS tailored for OT systems. This standard is widely used by transport infrastructure operators around the world to build a CSMS. Many authorities may not feel they are in a position to implement the full IEC 62443-2-1 standard, but the MfSS Cyber Security Guidance includes a lightweight set of security management recommendations that have been derived from IEC 62443 and NIST 800-160.

If you already have a security management system such as an ISMS, we recommend that you first check that it covers smart cities systems and then carry out a gap analysis between these elements and those in your current system.

We recommend a smart streets ready CSMS should include:

  • A rationale (see A2).
  • Defined roles and responsibilities for cyber security in the organisation (see A3).
  • A security assurance framework for authorising smart streets systems to be put into service (see A4).
  • A project management process that includes cyber security (see A5).
  • A plan for developing staff awareness and competence in cyber security (see A6).

 Applicable to:  All use cases
NCSC Connected Places CS Principles:
#1 Understanding your connected place and the potential impacts
#2 Understanding the risks to your connected place
#5 Understanding legal and regulatory requirements

Establishing cyber security culture within your organisation requires buy-in at all levels, and particularly from executive management. For this, a clear rationale should be defined, which essentially serves as your business case for being cyber secure. The NCSC Connected Places Cyber Security Guidance principles #1, #2 and #5 offer questions that should be considered when developing the cyber security rationale for a connected place.

You should define how cyber security supports the strategic goals of the organisation and how a lack of cyber security harms the goals. You should highlight the high-level risks posed by neglecting cyber threats. Cyber-attacks can have an impact on your authority’s finances, reputation and legal compliance, but can also have an impact on public safety, the environment and the local economy.

The case studies (1A and 2) and Recent Incidents section found in this guidance are intended to help you consider potential cyber risks and develop a rationale for your connected place cyber security management system. Based on the examples provided, you can consider the threat landscape at your own authority.

When identifying risks that you are trying to protect against, it is additionally important to understand your regulatory environment, particularly around cyber security, data privacy, safety and the environment. Individual smart streets systems may have specific regulatory and standards considerations. Some of these will be directly cyber security related such as the Data Protection Act 2018 (GDPR) for systems that handle personal data or PCI DSS for systems that process payments. Others such as the Environment Act 2021 are not cyber security-related, but a cyber-attack could indirectly cause non-compliance.

 Applicable to:  All use cases
NCSC Connected Places CS Principles:
#3 Understanding cyber security governance and skills

Security risk is ultimately owned by the chief executive of the authority, as the person with overall accountability to the local council. Individual business functions or projects may have direct risk owners with accountability for a specific scope. A security risk governance structure helps to inform risk owners and allow them to make confident decisions.

Within the security risk governance structure, it is essential that clear roles and responsibilities are defined for cyber security in the organisation. Leadership should, as a minimum, appoint a senior leader to have overall responsibility for cyber security (e.g. a Chief Information Security Officer, CISO) Beyond that, an organisational structure or network of people can be defined where security responsibilities for specific projects or disciplines can be delegated.

Example of how security roles and responsibilities could be defined at a high level.

The security officer for the organisation should enact cyber security policies and procedures to ensure security is considered from day one by new smart streets projects, and that existing projects and operations work to identify their security risks to inform the security officer. Some of the most critical security policies and procedures we recommend the authority’s security officer enact are a:

  • Policy that sets out required security activities across the project management lifecycle.
  • Procedure that describes the authority’s security assurance framework.
  • Policy that requires staff awareness training in engineering security.

 Applicable to:  All use cases
NCSC Connected Places CS Principles:
#3 Understanding cyber security governance and skills
#4 Understanding your suppliers’ role within your connected place

System assurance supports a risk owner in accepting that the risks of the system have been appropriately identified and managed, and that the residual risk meets the risk owner’s appetite.

The risk owner should be aware of cyber security risks and how they have been managed. However, the risk owner is generally not a cyber security expert, so a security assurance framework helps provide the risk owner assurance that good practice has been followed. Furthermore, a security assurance framework ensures that the supplier’s expectations are set regarding level to which they need to consider security and what deliverables they need to generate in order to gain the approval of the authority.

The security assurance framework should be flexible and provide different levels of assurance based on the criticality of the project so as to not create unnecessary costs. Typically, a short and simple security classification questionnaire should be completed at the start of a smart streets project to determine the potential for security risk. This is a consideration of the impact alone, with no consideration to likelihood, which may require a more in-depth assessment. Based on the potential for security risk, the project can be assigned a criticality.

The following table provides an example security classification questionnaire:

 

High
Criticality

(Full
Assurance
n)

Medium
Criticality

(Light
Assurance)

Low
Criticality

(Simple
Check)

What
is the worst case safety impact?

Likely
to cause injury or death in case of failure.

May have
an indirect safety impact in the event of failure.

No
safety impact would result from system failure.

Would
a breach lead to a disclosure of personally identifiable data and/or financial
risk?

Major violation of data protection regulations
and/or exposure to significant financial risk.

Minor violation of data protection regulations
and/or exposure to small financial risk.

No sensitive data could be exposed leading to a
violation of data protection regulations or a financial risk.

How
central is the system to the authority’s core mission?

Failure
would disrupt a most of the authority’s mission.

Failure
would disrupt a significant portion of the authority’s mission.

Failure would
not significantly disrupt the authority’s mission.

What
would be the impact of system failure on other systems?

Failure would have a widespread impact on other
systems or an impact on a high criticality system.

Another system or service may be impacted by
failure.

No other system would be impacted by a failure.

Does the system directly interface with a critical system?

Yes. A compromise of the system could potentially allow an attacker to launch a further attack on the critical system.

Only indirect interfaces to critical systems.

No interfaces to critical systems.  .

What
is the system complexity?

Complex
system made up of various hosts and multiple networks.

A system
made up of a fairly homogenous set of hosts with a limited number of data
paths.

An
individual product with limited scope and connectivity.

How
novel is the system?

A new type of system never before deployed.

A new type of system deployed by only a few authorities.

A mature type of system with a long established
track record.

What
is the likely publicity in the event of an incident?

Authority
likely to suffer significant negative publicity at the national level.

Authority
likely to suffer negative publicity locally.

Public
unlikely to notice or care.

 

Example
project:

New traffic
control system

CCTV
renewal

Vandalism
reporting webpage

Example OT security classification questionnaire.

Given that no project will perfectly fit one of the above criticalities, the authority can set rules regarding how a project is given a security classification. For example, points can be assigned to each answer with a threshold given for each level of criticality.

For each level of assurance, the framework should explain what an acceptable cyber security assurance case would include. It should set out your high-level expectations for the types of security activities that will be carried out and types of security deliverables that will be produced.

Given their size, local authorities must be particularly careful not each adopt widely varying requirements within their security assurance framework. Ideally, there would be a specific standard for smart streets or smart cities, but this is not currently the case. We recommend authorities keep their security assurance framework as generic and in line with NIST 800-160 and IEC 62443 as possible. National transport authorities such as Network Rail and National Highways typically already have a security assurance framework and specify that system suppliers must follow the framework. It may be advisable to work towards alignment with other national and local authorities through forums such as the Local Council Roads Innovation Group (LCRIG) and the Transport Technology Forum (TTF).

Below is an example of such a framework.

 

Phase

Min. Activities for
Full Assurance

Min. Activities for Light Assurance

Min.
Activities for Simple Check

Security
Concept

Allocate security role

Determine
security criticality

Security Definition

Conduct high-level threat and risk assessment
(if applicable)

Identify standard security considerations

Specify security
requirements

Secure
Procurement

Responsible engineer oversees purchasing

Secure Delivery

Conduct
detailed risk assessment

Review detailed security design

Conduct
security testing

Manage remediation

Plan for
vulnerability management and incident handling

Secure
Operation

Regular audit and review of the assurance case

Secure
Decommissioning

Manage
secure disposal

Example OT security assurance framework, minimum required activities.

 

 

Phase

Req. Deliverables for
Full Assurance

Req. Deliverables for Light Assurance

Req.
Deliverables for Simple Check

Security
Concept

Security Assurance Plan

Security Definition

High
Level Security Risk Report

Security Requirements Specification

Secure
Procurement

Secure Delivery

Security Implementation Plan

Detailed
Security Risk Report

Detailed Security Design

Security
Test Plan

Security test results and remediation evidence

Secure
Operation

Security
audit results

Secure
Decommissioning

Decommissioning Certificate

Example OT security assurance framework, required deliverables.

 Applicable to:  Owned and managed services
NCSC Connected Places CS Principles:
#3 Understanding cyber security governance and skills

An important part of establishing cyber security governance within your organisation is ensuring that projects take cyber security seriously and do not progress without identifying and managing security risks. Adding generic cyber security milestones to your organisation’s project management process and requiring them to be achieved to pass certain stage gates is a common method to achieve this.

The ideal approach is to align the project management process with the security assurance framework. However, it is a prerequisite that the authority have governance relating to project controls.

Enforcing Security Considerations for Very Small Projects

It is important that all smart streets projects, no matter the size, consider cyber security. The level to which cyber security is considered should be proportionate to the associated risks, but no project should be completely exempt based on size alone. As a minimum an upfront assessment should be performed and recorded to establish that no significant cybersecurity risks exist.

Observations in Part 1 demonstrate that small trial smart streets projects can evolve into larger, more permanent operations. If cyber security is not considered from the start, cyber security risks can be found later at a time when they become difficult and expensive to mitigate.

This does not mean that small projects can nor need to allocate significant funding to cyber security. Simple awareness of potential security risks can allow a trial system to be architected such that it is more feasible to address cyber security later.

Industry Lessons

A drone research company recently had limited funding to develop a demonstrator of a new unmanned aerial vehicle control system. Securing the demonstrator was not necessary for the trial, and it was undesirable to invest in the security of a project that may not be progressed. Under the guidance of their security officer, they followed the framework of an appropriate cyber security standard, but did not implement security measures. Because they followed the framework from project start and maintained an awareness of security, it was later a much simpler exercise to secure the system once the prototype was proven.

When there is a change in project scope, the security classification questionnaire should be revisited to avoid unmanaged scope creep.

 Applicable to:  All use cases
NCSC Connected Places CS Principles:
#3 Understanding cyber security governance and skills

An important part of building security maturity at your authority is ensuring that all staff have an awareness of cyber security and an understanding appropriate for their role. You should have a security training programme with different levels of training aimed at different groups of staff. Most authorities already have a general security awareness e-learning session targeted across all staff. This typically includes considerations such as avoiding phishing emails.

However, for project managers and engineers, more targeted training is needed. This is because these roles must now take on engineering security responsibilities, despite most having no background in cyber security. There are an increasing number of training courses available either based on IEC 62443 or tailored to smart cities cyber security. Suitable training courses would:

  • Focus on smart cities technologies, or otherwise focus on industrial / OT security.
  • Consider standards relevant to your use case(s), such as:
    • IEC 62443 – Relevant to any smart streets systems with a cyber physical element, e.g. ITS, traffic control, public transport, EV charging, etc.
    • PCI DSS – Relevant to smart streets systems involving payment cards.
    • ETSI EN 303 645 – Relevant to IoT devices being deployed in a smart streets environment.
  • Provide awareness of security considerations across the lifecycle including:
    • Cyber security risk management;
    • Secure architecture and design;
    • Secure configuration;
    • Vulnerability monitoring;
    • Incident handling;
    • Secure decommissioning.

It may also be advisable to target procurement staff with some security fundamentals training, so that when they need to support security-aware projects, they have an understanding of the vocabulary and concepts involved. However, we still expect that the project manager or engineer will need to take responsibility for ensuring purchasers consider security.

Off-the-shelf training courses targeted at connected places are currently rare. Thus, a common approach is to work with a cyber security consultant or training specialist to tailor existing generic and industrial cyber security syllabuses to the standards and applications applicable to the authority. Training is another area where authorities could benefit from a joint approach. If local authorities were to jointly procure smart cities or smart streets security training, or the training were arranged centrally, a better targeted course could be procured at a lower cost.

 Applicable to:  Owned and managed services
NCSC Connected Places CS Principles:
#3 Understanding cyber security governance and skills
#4 Understanding your suppliers’ role within your connected place
#12 Managing your connected place’s supply chain
#13 Managing your connected place throughout its life cycle

Smart street solutions are often reliant on many supply chain partners, such as product vendors, system integrators and service providers. These partners are essential to operating smart street services, however, reliance on the supply chain can also introduce cyber risk if not managed properly. It is important that authorities understand who their suppliers are, what subcontractors they rely on, what critical data and functions they handle, what security measures suppliers are contractually obliged to take, and what playbook is in place with suppliers in the event of a safety incident.

The NCSC recently released Supply Chain Mapping (SCM) guidance. Authorities should consider implementing this guidance within their supply chain management framework to prepare for the challenge of procuring from and relying on supply chain partners throughout the life cycle.

Country of Origin

Most products today come from a global supply chain, and the regulatory frameworks within which suppliers operate can introduce security risks. Regulations in some jurisdictions may force suppliers to secretly comply with government requests to plant deliberate security vulnerabilities, such as backdoors, in products. When managing supply chain security risks, authorities should be aware of this possibility.

Given that attempts to mitigate these risks can easily become intertwined with geopolitics, local authorities should take care when developing policies to blanket ban suppliers based on nationality. However, the risks should be considered:

  • Relations between the foreign government and the UK could deteriorate, leading to backdoors being exploited to inflict damage.
  • Relations between the foreign government and the UK could deteriorate, leading to the UK Government requiring immediate removal of certain products from systems.
  • Backdoors/vulnerabilities potentially present in these products could be used by attackers other than foreign intelligence agencies, with unknown effect.

The first two risks can be mitigated by preferring suppliers from countries that are considered to have compatibile values. However, this is a sensitive and specialist matter outside the scope of this guidance. The third risk can be mitigated by procuring products that have been subject to extensive independent testing. However, for many small products, this is not economically viable.

Data Sovereignty

Authorities whose supply chain includes cloud services should consider in which jusrisdictions data is processed and stored. Data is subject to the regulations of the jurisdiction where it is handled and kept. Processing data outside the UK may be incompatible with the Data Protection Act 2018 unless the other jurisdiction is approved by the UK government. Your procurement policy for cloud services should consider this.