Guidance
Security principles for cross domain solutions
Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).
Page 4 of 15
A CDS should provide a strong level of protection against attacks which use malicious content contained, even concealed, in data files, or other data constructs. Such attacks could adversely affect data processing on the receiving network, or the correct operation of the CDS itself.
In designing a CDS capable of defending against content based attacks, you should take into consideration the susceptibilities of the target system to content based attack. For instance, the complexity of the data formats being used.
Your design should take into account the capabilities and likelihood of any attacker performing such an attack. You should employ appropriate mitigations.
The potential for content based attacks on the CDS itself should also be kept in mind. For instance, the parsers that the CDS itself uses to process content should be robustly designed and implemented.
For more information on defending against content based attacks, please see the NCSC guidance on Safely Importing Data.

