A CDS should authenticate all user, equipment and internal component connection sessions before use.
User sessions should be authenticated to reduce the risk from unauthorised users. Equipment and connection sessions should be authenticated to reduce the risk of unauthorised systems using the CDS. Components within the CDS should be authenticated to each other, to ensure the flow of data and authorisations within the CDS are as intended.
Some forms of CDS will need to process data from unauthenticated sources, such as internet and email servers. Where possible, the CDS should at least implement industry best practice, for example using TLS for web servers, and DKIM / SPF/ DMARC / TLS for Email servers.
Defensive techniques
It should be possible to authenticate all user sessions to the CDS.
It should be possible to authenticate all system sessions to the CDS.
The system should support single sign-on technologies to avoid extra authentication effort for people, and the undesirable behaviours and outcomes that extra authentication may bring.
Components within the solution should authenticate with onward components, so that data will only transit through trusted paths.