Skip to main content

New cross domain guidance for government, industry and the wider security community

Ensuring cross domain technologies are better understood - and more easily deployed - across sectors.

Data flows between servers and a central processing unit, visualizing the intricate network of a complex data processing system analyzing information

Eugene Mymrin via Getty Images

Cross domain technologies play a vital role in helping organisations to move data safely between environments with different security levels. The NCSC know this area can be challenging to navigate, which is why we’ve produced new guidance on Cross domain approach and architecture. The guidance makes the adoption of cross domain technologies more straightforward and more secure.

This blog outlines what has changed, the reasons behind those changes, and what updates you can expect in the months ahead.


A brief history of cross domain

The NCSC and partners have developed cross domain solutions for many years, particularly in the defence and intelligence sectors. Organisations operating within these sectors have long required secure movement of data between systems operating at different security levels, and cross domain solutions have been central to meeting that need.

These solutions delivered significant benefits, including:

  • reduced cost by removing the need for isolated or duplicate systems
  • improved architectures that allow systems to work together more effectively

However, the threats we face today are more capable, more persistent, and more strategic. Systems that were never designed to operate in hostile environments are now targeted by sophisticated attackers, and organisations across sectors that were once unlikely targets — such as energy, industrial control, and wider elements of critical national infrastructure — are now firmly within scope. In fact, the new guidance should be used by any organisation where the threat model assumes systems will be under targeted attack, and the harm to the organisation from security compromise would be great (or where there is significant intellectual property).


Our new approach to cross domain

Many organisations contain systems that are interconnected in ways their designers never anticipated, and they rely on protocols that were not built to resist modern, sophisticated attacks. Attackers are increasingly able to uncover unknown vulnerabilities, and developments in AI will accelerate this further. Combined with supply chain changes that make it harder to gain deep assurance in products what are core to critical systems, cross domain is now an essential security approach for organisations operating across all sectors. 

Our revised guidance is designed to ensure that cross domain is easier to implement so it can be more widely adopted across disparate sectors. It reflects how modern systems operate and how organisations now use technology to deliver essential services. At its core, cross domain is about safely enabling business functions, even when those functions span systems with different levels of trust. This could include importing documents, enabling video communications, or interacting with services hosted in other environments, such as over APIs.

Rather than focusing on fixed boundaries or specific technologies, the new approach looks at the end‑to‑end architecture needed to make these functions secure and reliable. A central part of this approach is developing an explicit understanding of:

  • what data flows are required
  • how systems are connected
  • which threats are relevant, both individually and when systems are linked

Cross domain uses a sequence of functions—often referred to as a pipeline—to build confidence in data as it moves between trust zones. Each function prepares the data so the next stage can safely process it, or ensures that only valid data leaves a zone. This ensures assurance is gained across the entire flow, not at a single point.


Changes to the guidance

Our new guidance  will allow organisations to build systems that reflect the NCSC’s updated approach to cross domain. It explains essential concepts including zones of trust, trust boundaries, and control points. The guidance also reflects the need for flexible, layered controls, and largely replaces our older security principles for cross domain solutions. We do not recommend using the existing security principles for new end to end architectures, but they remain important for the NCSC’s Principles Based Assurance (PBA), so will be used to assure new cross domain products in the medium term.   

The NCSC’s original importing data and exporting data design patterns are being deprecated and in time will be replaced by new cross domain patterns. 

What’s next?

We will build on this guidance to provide more details on how to architect and implement cross domain products, and are looking to include topics such as:

  • a step-by-step guide to designing cross domain architectures, covering the key stages and considerations you need to take
  • guidance on selecting appropriate technology to implement dross domain functions
  • standardised cross domain patterns which will provide repeatable templates that will be applicable across a number of use cases

We’ll let you know when this guidance is ready. In the meantime, we hope you find the cross domain guidance useful when designing your organisation’s data flows across zones of trust.

 

Duncan M
Principal Security Architect 

Written by

Duncan M

Principal Security Architect, NCSC