A CDS should support data-in-transit protection (confidentiality, integrity and authentication) for all connections between components within the solution, and for external devices connecting to the CDS.
A CDS, by its very nature, will need to communicate with other systems, often over insecure networks. Compromise of a network connection could impact the integrity or confidentiality of the information being processed, so appropriate cryptographic protection is required. This may also apply to networking within the solution, depending on any additional controls in place.
Defensive techniques
Support point-to-point protection for connections made both into and out of the system (using technologies such as TLS).
Support point-to-point encryption for internal connections within the CDS, where there is a risk of 'man-in-the-middle' attacks undermining the end-to-end security of the system.
Support configuration of certificates for both network connections and root-of-trust.
Support certificate pinning and full certificate checking.
Support modern cryptographic standards and cypher suites.