Devices used in smart streets systems may contain sensitive data such as security credentials and network information that could be used by attackers and personal data that needs to be protected by law. You should follow a process when decommissioning hardware that ensures data is removed or otherwise rendered inaccessible.
| Applicable to: | Owned and managed services |
|---|
| NCSC Connected Places CS Principles: |
| #13 Managing your connected place throughout its life cycle |
When hardware and storage media may leave the system for different reasons. For example, an asset may need to be removed for maintenance purposes and sent to a third-party. An asset may be life-expired and due to be disposed of. An asset may be moved to another system.
Whichever the reason, the security of confidential data should be considered. Assets often contain credentials and/or personal data. Procedures should be put in place to identify and destroy such data before it leaves the authority’s custody. Procudures may involve logical or physical destruction of the data. However, care should be taken, as some methods such as simple file deletion may not physically remove the data.
It is worth noting that secure decommissioning guidance applies both to the decommissioning party and the recommissioning party. If an authority commissions a used/refurbished part in their system, they should they should follow procedures to ensure previous data is wiped. Old data may bring unexpected security risks.