Skip to main content
Guidance

Security principles for cross domain solutions

Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).

Page 13 of 15

Data-at-rest protection

A CDS should support data-at-rest protection for any sensitive data that needs to persist, where there is a risk the media could be copied or stolen. Examples of such data include business data, logs and configuration files. Additionally, the integrity of any audit logs should be maintained, as the integrity of these is a vital part of any system-wide monitoring.

Most CDS systems will need to cache and store some information locally, within the components of the CDS, on persistent media. In certain higher risk use cases, there is increased risk this media could be copied or stolen, so data-at-rest protection may be required, depending on the physical controls in place.

At-rest protections are vital to ensure protection when the system is inactive or switched off, but are less likely to mitigate loss of data if a running system is compromised.

Data-at-rest protection may also apply to software or firmware binaries within components.


Published

Reviewed

Version

1.0