Back

End User Device (EUD) Security Guidance

End User Device (EUD) Security Guidance

End User Device (EUD) Security Guidance

Status: Live
Published: 01/01/2019
Security level: Official
Amended / Internally developed: No
Live on platform: 23/03/21
Retired on platform:
Target Audience: Technical / General, Business / General
Authoring body: National Cyber security Centre (NCSC)
Grading: no grading applied
Principles
Abstract

The End User Device (EUD) Security Principles sets out 12 core guidance principles that underpin the safety and security of using devices that serve the purpose of working remotely. The twelve principles are as follows:

  1. Data-in-transit Protection

  2. Data-at-rest Protection

  3. Authentication

  4. Secure Boot

  5. Platform Integrity and Application Sandboxing

  6. Application allow Listing

  7. Malicious Code Detection and Prevention

  8. Security policy Enforcement

  9. External Interface Protection

  10. Device Update Policy

  11. Event Collection for Enterprise Analysis

  12. Incident Response

All of these principles must be considered when securing and deploying devices.

 

Category: Devices