Principles for secure privileged access workstations (PAWs)
Pages
Page 10 of 10
Principle 8: Control data entering and leaving the PAW solution
If you can’t trust files that are downloaded and then opened on your PAW device, they could be malicious and exploit your PAW.
Similarly, if a PAW is compromised, an attacker could abuse how your PAW exports data to exfiltrate sensitive information. For these reasons, you should carefully constrain and control how data is imported and exported from your PAW solution.
Building an effective process for important and exporting data is critical to enable your engineers to carry out their duties. Where this is not in place, users may resort to shadow IT.
An effective solution to manage your data effectively also helps you migrate away from the use of higher-risk transfer methods, such as removable media. Where it’s not possible to remove these methods from your environment, you should still apply the controls described in this principle. RITICS has guidance on managing removable media for ICS and OT environments that can support you here.
8.1 Secure use of enterprise file solutions
It’s important not to allow direct or unmanaged access directly from a PAW to your corporate file-sharing services. Examples of this could include mounting permissive network drives on your PAW, or directly accessing cloud-based file sharing services. Instead, make sure that importing and exporting data only takes place in line with a carefully managed import and export process.
Carrying out data transfers using your existing enterprise storage solution can present major risks to the PAW solution. These solutions are likely to introduce additional lateral movement routes between your enterprise and PAW environment. It can also be difficult to enable only the storage element of enterprise solutions, as it requires you to permit large amounts of internet-bound connections. Only use enterprise storage when you can be sure that:
- your enterprise and PAW identities remain segregated
- you have put in place mitigations to the risk of lateral movement
- enabling network connectivity to the enterprise storage solution does not allow new connectivity to any additional services
8.2 Effective import and export controls
When designing an import and export solution that is suitable for a PAW, start by identifying what types of data you need to share between your enterprise and PAW environments.
For example, complex data types, such as Word or PDF files, present greater risks that are typically harder to mitigate than structured data formats, such as XML or JSON. You should aim to minimise transfers to only what is essential, and where possible, consider converting to simpler data formats.
Your data transfer solution should:
- produce an audit trail so that you can account for all data entering and leaving your PAW environment
- require user authentication
- ensure only approved and authorised content is exported
- automate the transfer process to a defined pre-configured endpoint – the system should not allow export to arbitrary end points.
- inspect and scan the data for malicious content – this is partially important for data imported to the PAW. In some situations you may also want to validate the data structure.
The NCSC has separate guidance on how to safely import and export data from trusted environments as part of the cross domain solutions (CDS) guidance collection. Although these patterns are most effective when fully implemented where an organisation faces a lower threat, it’s possible to apply subsets of these patterns.
For high-threat use cases, data control solutions should, where feasible, be implemented in hardware following the NCSC CDS principles. Where the threat context is lower, software-based controls and network boundary restrictions may be suitable.


