Skip to main content
Guidance

Security principles for cross domain solutions

Thirteen things that need to be good to make a secure Cross Domain Solution (CDS).

Page 8 of 15

People and the CDS

A CDS must be usable by all the people who interact with it. This includes:

  • Installers of the system.
  • Administrators who have to look after the system.
  • People inside the organisation, who have to work with the tools every day.
  • People outside the organisation, for whom a CDS may be critical to working with people inside it.
  • Security staff monitoring the solution.

To be usable for all of these people (even if there are a lot of them, or it’s a large amount of work that people do with it), the CDS should be:

  • Effective – tasks can be completed to an acceptable quality or better (according to the system owners). This should take account of the outcome's accuracy and completeness. These standards apply to task people carry out directly with the CDS (such as sending information) and to the quality of the CDS’s outputs. For example, people inside the domain may be unable to carry out specific image analysis if details have been altered by security transformations. The CDS should also minimise the possibility of an action taken by a person, such as a mis-click, leading to a security incident.
  • Efficient – tasks can be completed in a timely fashion, with little effort or additional cost, so that people do not feel the need to find workarounds. The system should shepherd people away from errors by using contextual hints, and processes designed to make errors less likely. There should also be easy ways to recover from mistakes.
  • Satisfying – the experience of using the system meets the needs and expectations of its users. Peoples’ perceptions are important. Problems such as the unexpected alteration of files, or the fear that a file transfer may be stopped without notifications can make people seek workarounds, perhaps even avoiding the CDS entirely, resorting to less secure alternatives.
  • Accessible – A system which fails to be accessible quickly becomes inefficient and unsatisfying. For example, a file transfer system that converts text into images may make received documents impenetrable to search tools, as well as to screen readers. If the CDS cannot be made accessible then an alternate system should be available for people with accessibility requirements.

A CDS must be usable as a whole package. This includes hardware and software, documentation, training, and support services. Training and documentation can add only a little usability if this is missing in other parts of the CDS.


Published

Reviewed

Version

1.0