Based on information from Infosecurity Magazine, the UK's National Cyber Security Centre (NCSC) is calling on device manufacturers to enhance forensic observability in their products to aid incident response teams in evidence collection following a compromise.The NCSC highlights that network devices like firewalls and VPN gateways are increasingly targeted by attackers. Chris A, technical director at NCSC, stated that when incidents occur, organizations need reliable methods to understand what happened and assess device trustworthiness. Forensic observability, defined by the NCSC as providing telemetry, logging, configuration state, and the ability to collect forensic data from memory and at rest, is crucial for this. Manufacturers are urged to build supported mechanisms for gathering evidence, rather than defenders relying on reverse engineering or vulnerability research.The NCSC aims to dispel myths that observability aids attackers, deters customers, or is too difficult to implement, asserting that well-designed features enhance security and build trust. The agency is also collaborating with global partners to develop a reference architecture for forensic observability in network appliances.Source: Infosecurity Magazine
Incident Response
UK cybersecurity agency urges manufacturers to improve device forensic observability

Examiner pressing DIGITAL FORENSIC INVESTIGATION on a touch screen interface. Business metaphor and technology concept. Magnifying glass icons represent analytical tools for investigative techniques.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



