Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Select an option

  • Save timb-machine/66a8213f9e5d532cb9a478da3ae6c2fc to your computer and use it in GitHub Desktop.

Select an option

Save timb-machine/66a8213f9e5d532cb9a478da3ae6c2fc to your computer and use it in GitHub Desktop.
What requirements does ChatGPT think are critical to understand when deploying security solutions?
prompt: I often find that security solution requirements are based on features, not what the product use cases are or how it will be used. Write me 10 questions that would act as a good baseline for how security solutions should be built, administered and operated, based on requirements found in NCSC's Cyber Assessment Framework and NIS's CSF.
Yes. I’d frame these as **outcome/use-case questions**, rather than product-feature questions. That aligns particularly well with the NCSC CAF’s explicit outcome-focused approach and NIST CSF 2.0’s use of outcomes rather than prescribing particular technologies or processes. National Cyber Security Centre+2
## 10 baseline questions for a security solution
1. **What essential business function or security outcome is this solution intended to protect or enable?**\
Start with the thing that matters—service availability, confidentiality, integrity, safety, regulatory obligations, etc.—rather than the product category.
2. **What are the specific use cases and threat scenarios the solution must address?**\
Describe who or what is being protected, from what, under what circumstances, and what happens if the control fails.
3. **What assets, data, identities, systems and dependencies does the solution need to understand?**\
The solution should fit the organisation's actual technology and service dependencies, reflecting CAF's emphasis on understanding everything required to deliver and support essential functions. National Cyber Security Centre
4. **What security decisions or actions must the solution enable, and who is accountable for making them?**\
This shifts the requirement from _“does it have feature X?”_ to _“what decision does an operator need to make, and what information or automation enables it?”_
5. **How will the solution fit into the organisation's existing security processes and operating model?**\
Consider people, skills, workflows, escalation, ownership, integration and hand-offs—not just technical integration. CAF explicitly expects security policies, processes and procedures to be practical and embedded in organisational practice. National Cyber Security Centre
6. **What must be true for the solution to remain secure and effective during normal operation, change and failure?**\
Include secure configuration, updates, access control, resilience, dependencies, loss of connectivity, degraded operation and recovery. CAF specifically calls for resilience to be built into design, implementation, operation and management. National Cyber Security Centre
7. **How will the solution be administered securely, and how will administrative actions be controlled and evidenced?**\
Define privileged access, separation of duties, authentication, configuration management, auditability, change control and accountability.
8. **What must the solution detect, and how will its outputs become useful operational information?**\
Specify the events that matter, required telemetry, alerting, correlation, prioritisation, investigation and escalation. A large volume of technically accurate alerts is not necessarily a useful security outcome.
9. **How will we know that the solution is working and delivering the intended security outcome?**\
Define measurable outcomes, assurance, testing, coverage, performance, false positives/negatives, operational effectiveness and evidence for governance. This connects to NIST's emphasis on organisational profiles and communicating cybersecurity outcomes, rather than simply deploying controls. NIST Publications
10. **What happens when the solution—or the supplier supporting it—is compromised, unavailable or no longer fit for purpose?**\
Requirements should cover failure modes, alternative controls, recovery, exit/transition, supplier dependency and lessons learned. CAF explicitly treats supplier dependency as a security risk for which the organisation remains accountable. National Cyber Security Centre
### The underlying principle
I would turn those into a simple requirements rule:
> **Specify the security outcome, use case, operating context and evidence of effectiveness first; specify product features only where they are necessary to achieve those outcomes.**
That is quite close to the philosophy of both frameworks: **NCSC CAF v4.0** defines principles in terms of outcomes and deliberately avoids prescribing a particular way of achieving them, while **NIST CSF 2.0** similarly describes cybersecurity outcomes that organisations can achieve through different activities and technologies. National Cyber Security Centre+1
In practice, this gives you a useful hierarchy:
**Business/essential function → security outcome → use case/threat → operational process → required capability → implementation/feature**
rather than:
**Product → features → try to find a use for them.**
The NCSC CAF currently identifies four broad objectives—**managing security risk, protecting against cyber attacks, detecting events, and minimising incident impact**—which map neatly onto that lifecycle. National Cyber Security Centre
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment