Skip to content
This repository has been archived by the owner on May 24, 2022. It is now read-only.

Security: UKHomeOffice/technical-service-requirements

Security

docs/security.md

Security

As a Service, I should:

  • Follow the UK Home Office security guidelines for developers
  • Always use TLS 1.2 encryption to my service and to dependent services (even datastores)
  • Use SSO for users and not hold users locally
  • Have a way of providing auditable information on myself
  • Have authentication / authorization for dependent services where data needs to be protected

There aren’t any published security advisories