End User Device (EUD) Security Guidance
							Status: Live
							
						
									
						
							Published: 
							01/01/2019
						
					
						
							Security level: Official
						
					
						
							Amended / Internally developed: 
							False
						
					
						
						    Live on platform: 
							23/03/2021
						
					
				
							Target Audience: Technical / General, Business / General
						
					
						
							Authoring body: National Cyber security Centre (NCSC)
						
 
				
					
					
					
				    
    
				
					
					
						Grading: 
    						no grading applied
					
					
				
								Principles
							
						
		
						Abstract
							The End User Device (EUD) Security Principles sets out 12 core guidance principles that underpin the safety and security of using devices that serve the purpose of working remotely. The twelve principles are as follows:
- 
	
Data-in-transit Protection
 - 
	
Data-at-rest Protection
 - 
	
Authentication
 - 
	
Secure Boot
 - 
	
Platform Integrity and Application Sandboxing
 - 
	
Application allow Listing
 - 
	
Malicious Code Detection and Prevention
 - 
	
Security policy Enforcement
 - 
	
External Interface Protection
 - 
	
Device Update Policy
 - 
	
Event Collection for Enterprise Analysis
 - 
	
Incident Response
 
All of these principles must be considered when securing and deploying devices.
	
		
			
			
				
					Category:
					
						
						
							
								
									Devices