Skip to main content
Guidance

Security principles for cross domain solutions

Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).

Page 3 of 15

Network protocol attack protection

A number of components within your cross domain solution will need to communicate externally and hence could be targeted by attackers. It is therefore important to have a clear separation between these externally exposed components, and internal components which have connectivity to more protected core network systems and services. Between these two sets of components, controls need to be in place to prevent onward compromise.

In the context of this principle, “network protocol” refers to the underlying protocol(s) used to transfer data between components, along with any processing that is required. This will most likely be TCP/IP, but may be other, proprietary, protocols.

A CDS should provide strong protection against an attacker who might use the components within the solution as a route to compromise the core network. Components which connect differing security domains should be robust against attacks from the network.


Published

Reviewed

Version

1.0