Thus, this principle emphasises the need to configure systems according to installation and configuration guides. Common configuration mistakes include failure to remove known default passwords leaving a system trivially exploitable. Thus, EAL Certification without good configuration may provide a false sense of security. ISO/IEC 27001 and Common Criteria (CCRA 2009) require an assessment after a major upgrade or installation to verify that the changes have not weakened the system’s security controls. 10.2.1.8 Staff training Staff training closely links to configuration. Technical teams are more likely to make poor configuration choices if they lack training to enable them to understand security threats, risks and the need for mitigating controls. As recommended elsewhere, countries should train skilled professionals to manage assured products. The technical teams should have a business understanding of risk and expertise to deploy technological and network security technologies. As outlined under the Cybersecurity Skills and Training section, your organisation should have a clear plan to ensure that the security team maintains the requisite security skills. 10.2.1.9 Security Baselines Service minimisation is an example of good configuration. This principle requires that your IT teams create “Security Baselines” or “Builds” under which devices provide only the services required for business. Thus, as part of the compliance-checking framework, relevant stakeholders should validate that devices such as servers and end user computers run official services only and disable anything extra. Additionally, the service minimisation principle discourages the use of multi-purpose devices, where practical, as this increases system vulnerability and the impact of cyber attacks. For example, running web server, e-mail and file storage applications on a single device may appear cheap but this practice increases the security impacts of a successful cyber attack. 10.2.1.10 Aggregation This principle aims to prevent data aggregation risks. Data aggregation occurs when data that individually is of low classification obtains a higher Impact Level when combined with a large number of other data items. Aggregation occurs in two ways. Accumulation is a situation where increasingly large amounts of information stored together increases the overall Impact Level of compromise. Conversely, association is where the linking of different information assets, which individually have no or low Impact Level when compromised, but associated have a higher impact level of compromise. 58

Select target paragraph3