Compliance With the GCSx Code of Connection (GCSx CoCo) - What an IT Professional Needs to Know

The UK Government's initiative to prescribe a securityIntrusion Protection technology and with particular
standard to any organization accessing thefocus on Mobile/Remote Worker security.
Government Connect Secure Extranet is a movePolicies and Procedures, in particular Change
designed to keep government organisations one stepManagement Processes, approvals and
ahead of the inexorable increase in security threats.documentation.
There have been too many high profile data theftsConfiguration 'hardening', to ensure that known threats
and losses by Government organizations, highlightingand vulnerabilities are eliminated from all systems, with
both the risk to, and the importance of, ICT Securitya zealous patch management process combined with
and the governance of citizens' data.anti-virus technology, regularly tested and verified as
The result is the Government Connect Securesecure.
Extranet (GCSx). HM Government has mandated theStrong Monitoring for security incidents and events,
way in which public authorities and governmentwith all event logs being retained for 6 months
departments can securely transfer data betweenIn fact, the scope of the standard is quite similar in
each other.respect of its approach and its measures to the PCI
So, for example, how does a local authority needingDSS (The Payment Card Industry Data Security
Housing Benefits data access the Department forStandard), which is another security standard all local
Works and Pensions (DWP) database? Via the GCSxauthorities will now be familiar with. The PCI DSS is
of course!concerned with the secure governance of Payment
Similarly, Job Centre Plus communications with localCard data, and any 'card merchant' ie an organisation
authorities will only accept communications via thehandling payment card transactions, such as a District
GCSx, and likewise, communications with the Policecouncil collecting Council Tax, must comply with the
and the NHS will only be provided through thisdetails of the security standard.
connection.Therefore it makes sense to consider measures for
The concept is a "community of trust" and the GCSxCoCo compliance in the context as PCI DSS, since the
is one of a number of secure Government extranets,same technology that helps deliver CoCo compliance
including GSx, GSi and GCJx. See our Glossary ofshould be relevant for PCI DSS.
Terms at the end for details of these other networks.Is there a way to automate and simplify compliance?
So how does a district council access the GCSx? ViaConfiguration Change Tracking - once your firewalls,
a secure connection, the security of which is governedservers, switches, routers etc are all in a compliant
by the Code of Connection, or 'CoCo'.state you need to ensure they remain so. The only
The GCSx CoCoway to do this is to routinely verify the configuration
In England and Wales it is referred to as the GCSXsettings have not changed because unplanned,
Code of Connection (CoCo). In Scotland it is referredundocumented changes will always be made while
to as the GSX Code of Connection (CoCo).somebody has the admin rights to do so! We will alert
Through GCSx, local authorities can connect to thewhen any unplanned changes are detected to the
Government Secure Extranet (GSX) and Intranet(GSI),firewall, and any other network device within your
the National Health Service (NHS), Criminal Justice'Compliant Infrastructure'
Extranet (CJX), and the Police National Network (PNN).Planned Change Audit Trail - when changes do need
The Code of Connection takes into consideration howto be made to a device then you need to ensure that
best to protect the "community of trust" taking intochanges are approved and documented - ideally, you
account all potential threats, including:need an automated solution that make this
Attack from the GCSx itselfstraightforward, reconciling all changes made with the
Attack from the InternetRFC or Change Approval record
Mobile data theft and lossDevice 'Hardening' to be enforced and audited - The
Attack from the internal userbest solutions available today provide automated
Code of Connection (CoCo) for the Governmenttemplates for a hardened configuration for servers
Secure Intranet (GSI) and GCSx, Memorandumand desktops and network devices to show where
Number 22. According to CESG Infosec Memorandumwork is needed to get compliant, thereafter tracking all
Number 22, protective monitoring has traditionally beenplanned and unplanned changes that affect the
the most underrated and least effectively usedhardened status of your infrastructure. Specifically, the
security measure.state of the art in compliance auditing technology
The scope of the GCSx Code of Connection can becovers registry keys and values, file integrity, service
summarised as followsand process are whitelisting/blacklisting, user accounts,
Physical Security and Access Control, restrict andand installed software.
control access to the GCSx, including use of Firewalls,