Cross domain approach and architecture
How to safely enable data flows between areas of different trust within and between modern digital systems.
Page 2 of 5
What is cross domain?
Cross domain is an approach used to safely enable data flows between areas of different trust within and between modern digital systems. These areas, called 'zones of trust', are collections of systems or services that share a broadly similar security posture.
Every organisation operates and connects to multiple zones of trust, from internal business systems to cloud platforms and the internet, each carrying different levels of assurance and risk. The zones of trust may be completely within the organisations control, completely out of the organisations control or some combination thereof (such as a system on a public cloud platform). There is a ‘trust boundary’ wherever two zones of trust connect.
In most commercial environments, standard architectural good practice is usually sufficient to manage data flows between these zones. However, when you believe that some of your systems may be subject to targeted attack, and the data is sensitive or critical, the risks increase significantly. In these higher‑threat contexts, simple boundary controls are rarely enough. A cross domain approach can be used in these environments because it provides a deliberate, rigorous way to think about the risks of inter‑zone data movement, and to design controls that remain effective even when an adversary is actively trying to subvert them.
Ultimately, cross domain is about enabling essential business functions in a safe, manageable and threat‑aware way. It recognises that different parts of an architecture have different trust levels and that data flows between them must be carefully controlled when facing sophisticated or persistent threats.