Skip to main content
Guidance

Security principles for cross domain solutions

Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).

Page 11 of 15

Authentication

A CDS should authenticate all user, equipment and internal component connection sessions before use.

User sessions should be authenticated to reduce the risk from unauthorised users. Equipment and connection sessions should be authenticated to reduce the risk of unauthorised systems using the CDS. Components within the CDS should be authenticated to each other, to ensure the flow of data and authorisations within the CDS are as intended.

Some forms of CDS will need to process data from unauthenticated sources, such as internet and email servers. Where possible, the CDS should at least implement industry best practice, for example using TLS for web servers, and DKIM / SPF/ DMARC / TLS for Email servers.


Published

Reviewed

Version

1.0