Security principles for cross domain solutions
Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).
Pages
Page 2 of 15
Using the principles
The security principles for cross domain solutions will help you to develop and assess the security of a CDS, for a defined use-case.
Each principle describes a protection your CDS should provide against a given type of attack. Details of how this protection can be implemented are given as ‘defensive techniques’.
The defensive techniques described are not exhaustive, and depending on your threat environment, you may need to apply additional techniques. Conversely, not all of these techniques need to be applied for all risk or threat situations.
Each principle details defensive techniques for each threat. However, it's possible that the measures implemented to meet a particular threat for one principle will cover multiple principles. When assessing the overall security of the CDS, this should be taken into account.
To assess a CDS for a specific use case, the CDS should be measured against each principle. Evidence should be obtained which demonstrates the defensive measures that are in place, and their robustness. Understanding the level of protection provided by the CDS for each principle will lead to an overall view of how secure the CDS is.
Following an assessment using these principles, it is possible that further defensive measures will be identified, or further testing specified to better understand parts of the CDS.