10.2.1.3 Variable Depth Security or Zoning This security principle requires that cybersecurity solutions enforce sufficient separation between networks handling data of different protective marking levels. Security layering results in the ability to offer variable depth security. Each additional security level builds upon the capabilities of the layer below. As such, this principle requires the creation and the enforcement of zones for different levels of trust. For example, IT systems should require a Demilitarised Zone (DMZ) between zones to provide additional protection from untrusted services. Additionally, untrusted data should only enter the system in low risk zones. Untrusted data requires verification before elevation to a higher classification. 10.2.1.4 Defence in Depth To ensure that critical data receives sufficient protection even in face of increasingly sophisticated attacks, this principle requires the use of multiple controls and different security products to mitigate security threats collectively. For example, a network may implement firewalls, Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), content checkers and anti-virus software. If malicious code escaped the firewall rules and IDS/IPS controls, probably the content checker or anti-virus software may trap it. The principle also requires the sourcing of Security Enforcing Functions and devices from different manufacturers. Thus, this principle creates secure IT solutions because diversity means that there is more than one device in place and each is different. 10.2.1.5 Network Survivability Even Under Attack Recommendation ITU-T X.1205 defines a survivable network as one that continues to fulfil a minimum set of essential functionality in a timely manner in the presence of attacks. Survivable networks are able to deliver essential functionality in a timely manner even if parts of the network are unreachable or have failed due to an attack. Survivability is a feature that network designers can build into the infrastructure. The concept relies on the existence of a data classification scheme. Network segments reflect the Protective Marking Levels such as Not Protectively Marked, Restricted and Confidential. Thereafter, the engineers should define a strategy for dealing and recovering from attacks. 10.2.1.6 Independently Evaluated and Tested Products Another principle deals with the adequacy of security testing. We recommend that selectors of cybersecurity technologies aim to acquire assured products for Security Enforcing Functions throughout critical infrastructure. While the products that have Evaluation Assurance Level (EAL) are not automatically secure, they undergo rigorous testing and are likely to provide a solid foundation for security functions. Assured products are particularly vital in the enforcing of zone segregation. Additionally, Commercial off-the-Shelf (COTS) products are preferable to be-spoke solution as large vendors are more likely to have the resources and incentive to go through EAL testing. 10.2.1.7 IT System Configuration We would like to emphasise that EAL is not a security panacea. EAL markings only help if product configuration and use conforms to the Target of Evaluation (ToE) criteria. 57

Select target paragraph3