Part of Networks and connectivity standards
Security and compliance standards
Standards you should meet on access controls, authentication, configuration segmentation, remote access and perimeter security.
Note
These security standards align to the principles defined in the DSPT for networks and connectivity infrastructure. They do not replace organisational DSPT assessment requirements.
8.1 NHS organisations should employ Access Controls and Privileged Access standards for all networking equipment
Importance of meeting the standard
Network access controls help ensure that users, devices and services can only access the network resources they are authorised to use. In addition, privileged access to network infrastructure carries elevated risk and requires clear controls to reduce the likelihood and impact of misuse, error or compromise.
Consistent control of both standard and privileged access supports safe operation of clinical and non-clinical services and helps limit security incidents.
When to meet the standard
- designing or modifying network access policies
- providing user or device access to network assets
- granting administrative or support access to network infrastructure
- enabling third-party or supplier access
- reviewing network security controls and operational practices
How to meet the standard
You should apply access controls at appropriate network boundaries and ensure they are consistently enforced across wired, wireless, wide-area and remote connectivity. Privileged access to network infrastructure should be explicitly identified, restricted to authorised roles or individuals, and managed separately from standard user access where practicable.
Technical requirements to meet the standard
- control access at network edges and between network segments
- enforce least-privilege access to network services
- separate management access from user and service traffic
- apply role-based or context-aware access where appropriate
- log access control and policy enforcement events
- be limited to named roles or authorised individuals
- avoid shared or unmanaged administrative credentials
- use stronger authentication than standard access where practicable
- be logged and auditable
- be reviewed and revoked when no longer required
Controls implemented should be regularly reviewed in accordance with Cyber Assessment Framework (CAF), Data Security Protection Toolkit DSPT, and Network and Information Systems Regulations (NIS/NIS2) standards, to ensure compliance and the best security posture.
Aligns to the following DSPT principles:
| Principle | How it supports |
|---|---|
| Identity and access control |
Enforces strong authentication, separation of duties and reviewed administrative access. Supports least‑privilege access, role separation and auditability. |
Importance of meeting the standard
NHS sites will usually have a high number of different user and device types (staff, patients and public, visiting healthcare staff, and IoT and IoMT devices) accessing the network. Clear and consistent authentication approaches reduce the risk of unauthorised access, improve user experience, and support safe delivery of digital health services.
When to meet the standard
- deploying or upgrading Wi-Fi services
- introducing new user or device types to your Wi-Fi network
- implementing federated Wi-Fi roaming access or reviewing authentication
- approaches for existing wireless services
How to meet the standard
You should define authentication approaches appropriate to different user and device types and ensure these are consistently applied across services.
Authentication methods should support mobility, minimise intervention by users, and align with nationally recognised authentication standards where available.
Technical requirements to meet the standard
Wi-Fi authentication should distinguish between different user and device types (staff, patient and public, visiting healthcare staff and IoT devices).
- use the latest standards-based authentication methods and avoid pre-shared key authentication wherever possible
- support federated Wi-Fi access at sites where staff from other organisations visit
- enable central management of credentials and authentication policies
- support secure onboarding and revocation of access
Aligns to the following DSPT principles:
| Principle | How it supports |
|---|---|
| Identity and access control |
Supports modern identity‑based Wi‑Fi authentication, reducing weak‑credential risks. Enables consistent application of identity lifecycle and authentication policies. |
8.3 NHS organisations should keep an accurate record of all network devices and configurations
Importance of meeting the standard
Effective security relies on knowing what network assets exist, how they are configured, and who is responsible for them. Incomplete or outdated information increases operational risk and hinders effective response to incidents or failures.
When to meet the standard
- deploying new network infrastructure
- modifying existing network services or configurations
- entering or renewing supplier and support contracts
- reviewing operational resilience or security assurance
How to meet the standard
You should maintain accurate records of network assets, configurations, supplier network contracts or support arrangements and ensure this information is kept up to date throughout the asset lifecycle.
Technical requirements to meet the standard
- maintain an inventory of network infrastructure and connectivity services
- record ownership and support arrangements for all network devices
- maintain configurations for all network devices, including device type and location
- retain configuration backups and recovery information
- track all changes to network configurations over time
- use automated discovery tools where appropriate to enhance accuracy and efficiency
Aligns to the following DSPT principles:
| Principle | How it supports |
|---|---|
| Asset management | Ensures inventories, configurations, ownership and recovery data are maintained and accurate. |
8.4 NHS organisations should employ network segmentation and traffic separation across networks
Importance of meeting the standard
Network segmentation limits unnecessary access between systems, reduces the impact of security incidents and supports safe operation of clinical and non-clinical services. Clear separation of traffic helps protect sensitive systems while allowing shared use of network infrastructure for all user and device types.
When to meet the standard
- designing or modifying network architecture
- introducing new systems, services or device types
- reviewing your network security
How to meet the standard
You should design networks using logical separation to control how traffic flows between users, devices and services. Segmentation approaches should be consistent across fixed Wi-Fi networks and documented clearly for operational and assurance purposes.
Technical requirements to meet the standard
- separate network traffic for different user groups and device types as required for clinical and operational purposes, using standard capabilities such as Virtual Local Area Networks (VLAN) and Virtual Routing and Forwarding (VRF)
- use micro-segmentation for high-risk devices
- control access between network segments using defined policies
- support shared services without exposing unnecessary access
- extend consistently across site and inter-site connectivity
Aligns to the following DSPT principles:
| Principle | How it supports |
|---|---|
| System security | Applies zoning and traffic separation to reduce attack surface. |
| Resilient networks and systems | Limits the blast radius of failures or compromises. |
8.5 NHS organisations should provide secure remote access and external connectivity tools for staff working off-site
Importance of meeting the standard
NHS networks must securely connect staff, partners and external services while maintaining clear trust boundaries. Poorly controlled remote or external connectivity increases the risk of unauthorised access and lateral movement.
When to meet the standard
- providing remote access to NHS networks
- establishing site-to-site or partner connectivity
- enabling third-party support access
- reviewing network trust boundaries
How to meet the standard
You should use defined, managed approaches for remote and external connectivity that allow access to be controlled, monitored and revoked. Connectivity methods should be appropriate to the type of access being provided and consistent across the organisation.
Technical requirements to meet the standard
- use standards-based connectivity methods, such as VPNs
- enforce multi-factor authentication and session control
- limit access to required network resources
- support monitoring and termination of connections
- be documented and reviewed regularly
Aligns to the following DSPT principles:
| Principle | How it supports |
|---|---|
| Identity and access control | Ensures remote access is strongly authenticated and controlled. |
| Data security | Uses encryption to protect data sent over non‑trusted networks. |
8.6 NHS organisations’ networks should have robust, secure and resilient perimeter security
Importance of meeting the standard
A secure network perimeter is critical to protecting NHS systems, safeguarding patient data, and ensuring continuity of clinical and operational services. Effective perimeter security helps organisations:
- reduce exposure to internet‑based threats including malware, ransomware and targeted attacks
- defend against unauthorised access attempts
- mitigate distributed denial-of-service (DDoS), intrusion and reconnaissance activity
- detect and prevent sophisticated threats using advanced, multi‑layered controls
- meet cyber‑security obligations within DSPT and wider NHS security expectations
Modern perimeter defence requires a combination of firewalls, intrusion detection and prevention capabilities, continuous monitoring and national protective services, such as the NHS Secure Boundary and National Cyber Security Centre's (NCSC) Protective DNS Service.
When to meet the standard
- deploying or refreshing internet connectivity or perimeter equipment
- transitioning to Internet‑First, Zero Trust or SD‑Networking approaches
- upgrading legacy firewalls or security appliances
- responding to cyber risk assessments, DSPT findings, or resilience reviews
How to meet the standard
- perimeter protection is provided by a next‑generation firewall (NGFW) with deep inspection, application‑aware filtering and integrated threat‑prevention features (for example, intrusion detection system (IDS) or intrusion prevention system (IPS)
- intrusion attempts, suspicious activity, malware signatures and anomaly patterns are detected or blocked through IDS/IPS capabilities
- network perimeter events, logs and alerts are collected and monitored, preferably through a central SIEM or cloud‑based monitoring platform
- DDoS protection (provider‑based or appliance‑based) is implemented according to the site’s clinical dependency and risk profile
- access control policies are routinely reviewed and updated
- integration exists between perimeter controls and other parts of the security architecture (identity, segmentation, Zero Trust, secure remote access)
- the organisation evaluates and, where suitable, makes use of the NHS Secure Boundary. This provides national‑level threat protection, managed firewalling, web filtering, logging and centralised monitoring capabilities to support compliance with perimeter security requirements
Organisations should adopt an approach proportionate to their size, digital maturity and clinical context, ensuring both wired and wireless environments are protected.
Technical requirements to meet the standard
- deep packet inspection
- application identification and control
- integrated intrusion prevention
- threat intelligence feeds and signatures
- IDS and IPS capabilities that detect and prevent malicious traffic or abnormal activity at the perimeter
- secure remote access methods using modern VPN or identity‑centric authentication
- resilient design, including redundant perimeter hardware or failover paths where clinically required
- logging and event data export to a central SIEM or cloud‑based analytics platform
- DDoS mitigation (provider‑based or equivalent protection mechanisms)
- use of national services such as the NHS Secure Boundary to enhance protection, visibility and consistency across sites
Perimeter controls should be reviewed regularly, tested as part of cyber and resilience exercises, and updated in line with emerging threats.
Aligns to the following DSPT principles:
| Principle | How it supports |
|---|---|
| System security | Establishes strong boundary controls and zoning. Ensures NGFW/IDS/IPS are configured, maintained and updated securely. |
| Resilient networks and systems | Provides DDoS protection and failover capability for perimeter services. |
| Security monitoring | Enhances logging, alerting, secure retention and incident detection at the perimeter. |
Last edited: 6 August 2026 1:42 pm