Amid the ongoing focus on the resiliency of companies' IT systems and the increasing popularity of cloud based solutions, two UK bodies have published updates to their security guidance.
The UK’s National Cyber Security Centre ("NCSC") has updated its cloud security guidance to support organisations in migrating their services and sensitive data into the cloud, including the addition of a new section on selecting the appropriate cloud provider for a business's security needs.
Meanwhile, the Department for Digital, Culture, Media & Sport ("DCMS") has published a consultation seeking views on proposals to improve the privacy and security of app stores and apps, with proposals including a 'world-first' code of practice to ensure there are minimum privacy and security levels required for app store developers and operators.
The above initiatives present further examples of the Government trying to balance the need for innovation against the security and safety of the data and material being processed. Takeaway points from the NCSC guidance include that an organisation is responsible for selecting a cloud provider that aligns with its security requirements, and that an organisation's use of the service can undermine how secure content is in the cloud.
Feedback on the DCMS' proposals can be submitted until 29 June 2022. In particular, the Government has highlighted that it is also eager to gain views in relation to feedback and review processes developers have experienced whilst creating apps on various app stores. Following receipt of feedback, the Government has suggested the code might be published this year.