A CDS should be simply and securely managed, through all stages of its life-cycle (such as initial deployment, update, and day-to-day management). Compromising the management plane can undermine the security of the system.
Defensive techniques
Management traffic should be separated from business traffic at all network layers, using techniques such as separate interfaces, restricting IP addresses which can connect to the management interface, and separate network processing software instances.
Lower trust components should never be able to manage or influence a higher trust component.
If a lower trust component is managed by a higher trust component, there should be protection against network and content based attacks from the less trusted component.
Management interfaces should be authenticated.
Management interfaces should use commercial data-in-transit encryption (such as TLS).
Management commands and configuration changes should be audited.