Guidance
Security principles for cross domain solutions
Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).
Page 3 of 15
A number of components within your cross domain solution will need to communicate externally and hence could be targeted by attackers. It is therefore important to have a clear separation between these externally exposed components, and internal components which have connectivity to more protected core network systems and services. Between these two sets of components, controls need to be in place to prevent onward compromise.
In the context of this principle, “network protocol” refers to the underlying protocol(s) used to transfer data between components, along with any processing that is required. This will most likely be TCP/IP, but may be other, proprietary, protocols.
A CDS should provide strong protection against an attacker who might use the components within the solution as a route to compromise the core network. Components which connect differing security domains should be robust against attacks from the network.
For more information on defending against network protocol attacks on an import flow, including the use of Protocol Break technology please see the NCSC guidance on Safely Importing Data. For more information on defending against network protocol attacks for export, please see Safely Exporting Data.

