Skip to main content

Part of Networks and connectivity standards

Security and compliance standards

Current Chapter

Current chapter – Security and compliance standards


Standards you should meet on access controls, authentication, configuration segmentation, remote access and perimeter security.

Note

These security standards align to the principles defined in the DSPT for networks and connectivity infrastructure. They do not replace organisational DSPT assessment requirements.


8.1 NHS organisations should employ Access Controls and Privileged Access standards for all networking equipment

Importance of meeting the standard

Network access controls help ensure that users, devices and services can only access the network resources they are authorised to use. In addition, privileged access to network infrastructure carries elevated risk and requires clear controls to reduce the likelihood and impact of misuse, error or compromise.

Consistent control of both standard and privileged access supports safe operation of clinical and non-clinical services and helps limit security incidents.

When to meet the standard

You should meet this standard when
  • designing or modifying network access policies
  • providing user or device access to network assets
  • granting administrative or support access to network infrastructure
  • enabling third-party or supplier access
  • reviewing network security controls and operational practices

How to meet the standard

You should apply access controls at appropriate network boundaries and ensure they are consistently enforced across wired, wireless, wide-area and remote connectivity. Privileged access to network infrastructure should be explicitly identified, restricted to authorised roles or individuals, and managed separately from standard user access where practicable.

Technical requirements to meet the standard

Network access controls should
  • control access at network edges and between network segments
  • enforce least-privilege access to network services
  • separate management access from user and service traffic
  • apply role-based or context-aware access where appropriate
  • log access control and policy enforcement events
Privileged access to network infrastructure should
  • be limited to named roles or authorised individuals
  • avoid shared or unmanaged administrative credentials
  • use stronger authentication than standard access where practicable
  • be logged and auditable
  • be reviewed and revoked when no longer required

Controls implemented should be regularly reviewed in accordance with Cyber Assessment Framework (CAF), Data Security Protection Toolkit DSPT, and Network and Information Systems Regulations (NIS/NIS2) standards, to ensure compliance and the best security posture. 

Aligns to the following DSPT principles:

Principle How it supports
Identity and access control

Enforces strong authentication, separation of duties and reviewed administrative access. 

Supports least‑privilege access, role separation and auditability.


8.2 NHS organisations should use robust Wi-Fi authentication to reduce risk of unauthorised access

Importance of meeting the standard

NHS sites will usually have a high number of different user and device types (staff, patients and public, visiting healthcare staff, and IoT and IoMT devices) accessing the network.  Clear and consistent authentication approaches reduce the risk of unauthorised access, improve user experience, and support safe delivery of digital health services.

When to meet the standard

You should meet this standard when
  • deploying or upgrading Wi-Fi services
  • introducing new user or device types to your Wi-Fi network
  • implementing federated Wi-Fi roaming access or reviewing authentication
  • approaches for existing wireless services

How to meet the standard

You should define authentication approaches appropriate to different user and device types and ensure these are consistently applied across services.

Authentication methods should support mobility, minimise intervention by users, and align with nationally recognised authentication standards where available.

Technical requirements to meet the standard

Wi-Fi authentication should distinguish between different user and device types (staff, patient and public, visiting healthcare staff and IoT devices).

You should
  • use the latest standards-based authentication methods and avoid pre-shared key authentication wherever possible
  • support federated Wi-Fi access at sites where staff from other organisations visit
  • enable central management of credentials and authentication policies
  • support secure onboarding and revocation of access

Aligns to the following DSPT principles:

Principle How it supports
Identity and access control

Supports modern identity‑based Wi‑Fi authentication, reducing weak‑credential risks.

Enables consistent application of identity lifecycle and authentication policies.


8.3 NHS organisations should keep an accurate record of all network devices and configurations

Importance of meeting the standard

Effective security relies on knowing what network assets exist, how they are configured, and who is responsible for them. Incomplete or outdated information increases operational risk and hinders effective response to incidents or failures.

When to meet the standard

You should meet this standard when
  • deploying new network infrastructure
  • modifying existing network services or configurations
  • entering or renewing supplier and support contracts
  • reviewing operational resilience or security assurance

How to meet the standard

You should maintain accurate records of network assets, configurations, supplier network contracts or support arrangements and ensure this information is kept up to date throughout the asset lifecycle.

Technical requirements to meet the standard

Network asset and configuration management should
  • maintain an inventory of network infrastructure and connectivity services
  • record ownership and support arrangements for all network devices
  • maintain configurations for all network devices, including device type and location
  • retain configuration backups and recovery information
  • track all changes to network configurations over time
  • use automated discovery tools where appropriate to enhance accuracy and efficiency

Aligns to the following DSPT principles:

Principle How it supports
Asset management Ensures inventories, configurations, ownership and recovery data are maintained and accurate.

8.4 NHS organisations should employ network segmentation and traffic separation across networks

Importance of meeting the standard

Network segmentation limits unnecessary access between systems, reduces the impact of security incidents and supports safe operation of clinical and non-clinical services. Clear separation of traffic helps protect sensitive systems while allowing shared use of network infrastructure for all user and device types.

When to meet the standard

You should meet this standard when
  • designing or modifying network architecture
  • introducing new systems, services or device types
  • reviewing your network security

How to meet the standard

You should design networks using logical separation to control how traffic flows between users, devices and services. Segmentation approaches should be consistent across fixed Wi-Fi networks and documented clearly for operational and assurance purposes.

Technical requirements to meet the standard

Network segmentation should
  • separate network traffic for different user groups and device types as required for clinical and operational purposes, using standard capabilities such as Virtual Local Area Networks (VLAN) and Virtual Routing and Forwarding (VRF)
  • use micro-segmentation for high-risk devices
  • control access between network segments using defined policies
  • support shared services without exposing unnecessary access
  • extend consistently across site and inter-site connectivity

Aligns to the following DSPT principles:

Principle How it supports
System security Applies zoning and traffic separation to reduce attack surface.
Resilient networks and systems Limits the blast radius of failures or compromises.

8.5 NHS organisations should provide secure remote access and external connectivity tools for staff working off-site

Importance of meeting the standard

NHS networks must securely connect staff, partners and external services while maintaining clear trust boundaries. Poorly controlled remote or external connectivity increases the risk of unauthorised access and lateral movement.

When to meet the standard

You should meet this standard when
  • providing remote access to NHS networks
  • establishing site-to-site or partner connectivity
  • enabling third-party support access
  • reviewing network trust boundaries

How to meet the standard

You should use defined, managed approaches for remote and external connectivity that allow access to be controlled, monitored and revoked. Connectivity methods should be appropriate to the type of access being provided and consistent across the organisation.

Technical requirements to meet the standard

Secure remote and external connectivity should
  • use standards-based connectivity methods, such as VPNs
  • enforce multi-factor authentication and session control
  • limit access to required network resources
  • support monitoring and termination of connections
  • be documented and reviewed regularly

Aligns to the following DSPT principles:

Principle How it supports
Identity and access control Ensures remote access is strongly authenticated and controlled.
Data security Uses encryption to protect data sent over non‑trusted networks.

8.6 NHS organisations’ networks should have robust, secure and resilient perimeter security

Importance of meeting the standard

A secure network perimeter is critical to protecting NHS systems, safeguarding patient data, and ensuring continuity of clinical and operational services. Effective perimeter security helps organisations:

  • reduce exposure to internet‑based threats including malware, ransomware and targeted attacks
  • defend against unauthorised access attempts
  • mitigate distributed denial-of-service (DDoS), intrusion and reconnaissance activity
  • detect and prevent sophisticated threats using advanced, multi‑layered controls
  • meet cyber‑security obligations within DSPT and wider NHS security expectations

Modern perimeter defence requires a combination of firewalls, intrusion detection and prevention capabilities, continuous monitoring and national protective services, such as the NHS Secure Boundary and National Cyber Security Centre's (NCSC) Protective DNS Service.

When to meet the standard

You should meet this standard when
  • deploying or refreshing internet connectivity or perimeter equipment
  • transitioning to Internet‑First, Zero Trust or SD‑Networking approaches
  • upgrading legacy firewalls or security appliances
  • responding to cyber risk assessments, DSPT findings, or resilience reviews

How to meet the standard

You should work with your security, network and supplier teams to ensure
  • perimeter protection is provided by a next‑generation firewall (NGFW) with deep inspection, application‑aware filtering and integrated threat‑prevention features (for example, intrusion detection system (IDS) or intrusion prevention system (IPS)
  • intrusion attempts, suspicious activity, malware signatures and anomaly patterns are detected or blocked through IDS/IPS capabilities 
  • network perimeter events, logs and alerts are collected and monitored, preferably through a central SIEM or cloud‑based monitoring platform
  • DDoS protection (provider‑based or appliance‑based) is implemented according to the site’s clinical dependency and risk profile
  • access control policies are routinely reviewed and updated
  • integration exists between perimeter controls and other parts of the security architecture (identity, segmentation, Zero Trust, secure remote access)
  • the organisation evaluates and, where suitable, makes use of the NHS Secure Boundary. This provides national‑level threat protection, managed firewalling, web filtering, logging and centralised monitoring capabilities to support compliance with perimeter security requirements

Organisations should adopt an approach proportionate to their size, digital maturity and clinical context, ensuring both wired and wireless environments are protected.

Technical requirements to meet the standard

To meet this standard, perimeter security should include a next‑generation firewall capable of
  • deep packet inspection
  • application identification and control
  • integrated intrusion prevention
  • threat intelligence feeds and signatures
It should also include
  • IDS and IPS capabilities that detect and prevent malicious traffic or abnormal activity at the perimeter
  • secure remote access methods using modern VPN or identity‑centric authentication
  • resilient design, including redundant perimeter hardware or failover paths where clinically required
  • logging and event data export to a central SIEM or cloud‑based analytics platform
  • DDoS mitigation (provider‑based or equivalent protection mechanisms)
  • use of national services such as the NHS Secure Boundary to enhance protection, visibility and consistency across sites

Perimeter controls should be reviewed regularly, tested as part of cyber and resilience exercises, and updated in line with emerging threats.

Aligns to the following DSPT principles:

Principle How it supports
System security Establishes strong boundary controls and zoning.
Ensures NGFW/IDS/IPS are configured, maintained and updated securely.
Resilient networks and systems Provides DDoS protection and failover capability for perimeter services.
Security monitoring Enhances logging, alerting, secure retention and incident detection at the perimeter.

Last edited: 6 August 2026 1:42 pm