10.2.1.3 Variable Depth Security or Zoning
This security principle requires that cybersecurity solutions enforce sufficient separation
between networks handling data of different protective marking levels. Security layering
results in the ability to offer variable depth security. Each additional security level builds
upon the capabilities of the layer below. As such, this principle requires the creation and
the enforcement of zones for different levels of trust. For example, IT systems should
require a Demilitarised Zone (DMZ) between zones to provide additional protection from
untrusted services. Additionally, untrusted data should only enter the system in low risk
zones. Untrusted data requires verification before elevation to a higher classification.
10.2.1.4 Defence in Depth
To ensure that critical data receives sufficient protection even in face of increasingly
sophisticated attacks, this principle requires the use of multiple controls and different
security products to mitigate security threats collectively. For example, a network may
implement firewalls, Intrusion Detection Systems (IDS), Intrusion Prevention Systems
(IPS), content checkers and anti-virus software. If malicious code escaped the firewall
rules and IDS/IPS controls, probably the content checker or anti-virus software may trap
it. The principle also requires the sourcing of Security Enforcing Functions and devices
from different manufacturers. Thus, this principle creates secure IT solutions because
diversity means that there is more than one device in place and each is different.
10.2.1.5 Network Survivability Even Under Attack
Recommendation ITU-T X.1205 defines a survivable network as one that continues to
fulfil a minimum set of essential functionality in a timely manner in the presence of
attacks. Survivable networks are able to deliver essential functionality in a timely manner
even if parts of the network are unreachable or have failed due to an attack. Survivability
is a feature that network designers can build into the infrastructure. The concept relies on
the existence of a data classification scheme. Network segments reflect the Protective
Marking Levels such as Not Protectively Marked, Restricted and Confidential. Thereafter,
the engineers should define a strategy for dealing and recovering from attacks.
10.2.1.6 Independently Evaluated and Tested Products
Another principle deals with the adequacy of security testing. We recommend that
selectors of cybersecurity technologies aim to acquire assured products for Security
Enforcing Functions throughout critical infrastructure. While the products that have
Evaluation Assurance Level (EAL) are not automatically secure, they undergo rigorous
testing and are likely to provide a solid foundation for security functions. Assured
products are particularly vital in the enforcing of zone segregation. Additionally,
Commercial off-the-Shelf (COTS) products are preferable to be-spoke solution as large
vendors are more likely to have the resources and incentive to go through EAL testing.
10.2.1.7 IT System Configuration
We would like to emphasise that EAL is not a security panacea. EAL markings only help
if product configuration and use conforms to the Target of Evaluation (ToE) criteria.
57