A CDS should provide protections against persistent compromise. This ensures the integrity of the CDS, and that it performs the security functions it was designed to.
Defensive techniques
It should be possible to return the system to a known good state.
The execution environment of software components, which interpret complex data, should be reset to a known good state prior to starting those software components.
The integrity of components should be monitored and appropriate action taken if this is compromised. If components are able to monitor their own integrity, they should do so, otherwise the wider system should perform this function.