The British Security Industry Association (BSIA) has published guidelines to help organisations limit their exposure to digital sabotage.
The 335 Cyber Secure it – Best Practice Guidelines for Connected Security Systems document summarises current guidelines, which aim to minimise risks to network-connected equipment, as well as systems and software used in electronic security.
These guidelines, the association said, are intended to be used “by organisations and stakeholders involved in the manufacture, supply, installation, maintenance and inspection of electronic security systems,” – along with end users and those involved in remotely monitoring such systems.
The BSIA is the trade association representing more than 70% of the UK’s private security industry, with members specialising in all sectors for security.
Industry Best Practice
Guidelines set out by the BSIA are based on international industry best practice, drawing upon recognised international guidance and standards which it says “will assist the supply chain in their duty of care to other network users, particularly with respect to protecting the integrity of existing cybersecurity countermeasures.”
Read more: In 2019, Marketing Could Learn A Lot from the Punk Era
Steve Lampett, technical services manager at BSIA, believes the guidelines will enable organisations to provide more effective security solutions and prove to be a crucial guide for industry practitioners.
He said: “We think that Cyber Secure it – Best Practice Guidelines for Connected Security Systems will become an invaluable guide for our industry practitioners and stakeholders alike as technology continues to evolve and the internet is used to provide a better end-user experience.
“This will enable us to better serve our industry consumers by providing professional, safe and secure internet enabled security solutions.”
Ensuring Data Integrity
Recommendations in the document underline the importance of data integrity management at an organisational level, with GDPR compliance a critical factor.
Guidelines suggest that the storage of data on a remote device should be “kept to a minimum and should be encrypted” while also recommending that data transmitted across remote connections should be encrypted.
Additionally, organisations should ensure the decommissioning of data is compliant with data protection regulations – specifically GDPR.
“A decommissioning function should be included to erase/overwrite all configuration and/or personal data,” the document reads.
User responsibility is also a key focus of the document, outlining a series of guidelines through which users can ensure organisational integrity.
Where users have agreed to take responsibility, the document says, the guidelines are intended to assist in the management of routine operation of a security network or system, with the following responsibilities defined or assigned accordingly.
- Maintain and manage an inventory of security devices on a security network
- Maintain and manage an inventory of authorised software applications running on security-related devices
The preparation and testing of contingency plans, specifically a cybersecurity incident response plan is a key responsibility laid out in the document.
The full guidelines can be downloaded here.





