Procurement of a smart streets system generally involves the authority’s commercial and procurement teams. These teams often have limited cyber security awareness, and it is recommended that members of the IT security team and/or the responsible engineer collaborate to ensure a secure outcome. The authority should aim to differentiate between bidders based not only on price and performance, but also security.

The desired outcomes of the secure procurement phase include:

  • Security considerations are included in the request for a supplier to provide a product or service.
  • Security considerations are included in the criteria for selecting a supplier.
  • The agreement between the authority and the supplier contains security considerations.

Authorities generally already judge a suppliers on whether they implement ISO 27001 or Cyber Essentials. However, compliance with these standards only indicates that the organisation keeps data secure, not that they understand or follow good practice around product or system security engineering. It is these considerations above those standard information security ones that should be assessed.

More detailed guidance on securely managing procurement processes can be found in the NCSC Principles of Supply Chain Security  and the acquisition process guidance of NIST 800-160 vol. 1. Public procurement is a regulated activity, so it is important to ensure this guidance is implemented in accordance with the law.

Three types of procurement should be considered: The procurement of system design, integration and operation, the procurement of products, and the procurement of related services.

 Applicable to: Owned and managed services
NCSC Connected Places CS Principles:
#12 Managing your connected place’s supply chain
#13 Managing your connected place throughout its life cycle

For many smart streets procurement activities, the most efficient way to securely purchase is to identify relevant security standards and guidance. Depending on the type of solution, product or service, different standards and guidance may be relevant.

There are two types of standards and guidance to consider: generic and application-specific. Security standardisation in smart streets and smart cities is still a developing area, and there are sometimes multiple similar standards in the same space. For this reason, it may be advisable to specify that similar or equivalent standards are acceptable.

Generic Security Standards and Guidance

Generic standards and guidance are not specific to smart streets applications.

For any project involving what could be classed as IoT devices, below are some of the most widely used examples:

Note that legislation is around IoT security is currently evolving in both the UK and the European Union. The new Product Security and Telecommunications Infrastructure Act in the UK sets security requirements for IoT devices, but the regulatory scope only covers consumer products. Nevertheless, the DCMS Code of Practice for Consumer IoT Security from which the act was derived should be considered as a minimum requirement for smart streets IoT. The EU’s proposed Cyber Resilience Act aims to one day introduce minimum security requirements for CE-marked connected devices.

For projects that involve SCADA and OT type technology such as traffic management and control, IEC 62443-4-1 (Secure product development lifecycle requirements) and -4-2 (Technical security requirements for IACS components) are the most applicable generic standards. However, following generic guidance can be seen as quite complex, therefore it is likely that SMEs will seek to adopt only subsets relevant to their specific product. You should ask your SME suppliers to map their secure development process to the IEC 62443-4-1 and -4-2 standards where possible to ensure coverage.

For projects where a system integrator is involved and will be responsible for security risk management and assurance activities, the following standards are relevant:

  • IEC 62443-2-1 – Establishing an industrial automation and control systems security programme
  • IEC 62443-2-4 – Security programme requirements for IACS service providers
  • IEC 62443-3-3 – System security requirements and security levels
Application-Specific Security Standards and Guidance

Sometimes, there may be specific security guidance for a particular smart streets use case. One example is NEMA TS 8 (Cyber and Physical Security for ITS). The Transport Technology Forum (TTF) Cyber Security Signposting Guidance is a useful resource to search for application-specific security standards.

 Applicable to: Owned and managed services
NCSC Connected Places CS Principles:
#12 Managing your connected place’s supply chain

The Crown Commercial Service (CCS) is the UK government agency responsible for supporting the procurement of products and services. They provide a service to facilitate the purchase of Transport Technology & Associated Services (TTAS), including most smart streets use cases.

The TTAS framework offers a call off contract specific to cyber security that can be customised with an initial security plan and a set of security requirements.

When using TTAS to procure a service for the delivery of a smart streets solution, the security assurance plan prepared for the project can be included in the cyber security call off contract. The standard terms of the contract require the supplier to base their security management plan on this, which fits with the standards-based approach suggested in this guidance.

Any security requirements identified in the previous phase or relevant standards can also be included in the call off contract.

Many products related to smart streets solutions such as CCTV cameras intended for ANPR systems are available to procure through TTAS.

If not using TTAS, many standard procurement contracts are similar. Review the security call off contract on the TTAS website and determine whether a similar contract is possible under your authority’s framework.