THE UK’s National Cyber Security Centre (NCSC) is urging device manufacturers to enhance 'forensic observability' in network devices to aid incident response teams in collecting post-compromise evidence. This approach emphasizes the need for built-in capabilities like telemetry, logging, and the ability to retrieve forensic data to ensure a device's trustworthiness.
The NCSC dispelled myths about observability hindering security and encouraged manufacturers to adopt its guidelines, asserting that effective forensic observability can bolster security rather than compromise it.