<section title="19.4. Diodes"><subsection title="Objective"><paragraph
    title="19.4.1."


><![CDATA[<p>Networks connected to one-way (uni-directional) gateways implement diodes in order to protect the higher classified system.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="19.4.2."


><![CDATA[<p>This section covers information relating to filtering requirements for one-way gateways used to facilitate data transfers.&nbsp; Additional information that also applies to topics covered in the section can be found in:</p><ul>
<li><a href="http://nzism.gcsb.govt.nz/ism-document#Chapter-14397">Chapter 12 – Product Security </a>which provides advice on selecting evaluated products.</li>
<li><a href="http://nzism.gcsb.govt.nz/ism-document#Section-16836">Section 20.1 – Data Transfers</a>; and</li>
<li><a href="http://nzism.gcsb.govt.nz/ism-document#Section-16876">Section 20.2 – Data Import and Export</a>;</li>
</ul>]]></paragraph>
</block>
</subsection>
<subsection title="References"><paragraph
    title="19.4.3."


><![CDATA[<p>Further information on the Evaluated Products List can be found at:</p><table class="table-main">
<tbody>
<tr>
<td style="text-align: center;"><strong>Reference</strong></td>
<td style="text-align: center;"><strong>Title</strong></td>
<td style="text-align: center;"><strong>Publisher</strong></td>
<td style="text-align: center;"><strong>Source</strong></td>
</tr>
<tr>
<td>&nbsp;</td>
<td><strong>Evaluated Products List (EPL)</strong></td>
<td style="text-align: center;">AISEP</td>
<td><a title="EPL" rel="noopener noreferrer" href="https://www.cyber.gov.au/acsc/view-all-content/epl-products" target="_blank">https://www.cyber.gov.au/acsc/view-all-content/epl-products</a></td>
</tr>
</tbody>
</table>]]></paragraph>
 </subsection>
<subsection title="Rationale &amp; Controls"> <block title="Diode assurance levels"><paragraph
    title="19.4.4.R.01."

    tags="Technical,Gateway Security"


><![CDATA[<p style="text-align: left;">A diode enforces one-way flow of network traffic thus requiring separate paths for incoming and outgoing data.  As such, it is much more difficult for an attacker to use the same path to both launch an attack and release the information.  Using diodes of higher assurance levels for higher classified networks provides an appropriate level of assurance to agencies that the specified security functionality of the product will operate as claimed.</p>]]></paragraph>
<paragraph
    title="19.4.4.C.01."

    tags="Technical,Gateway Security"


    classification="All Classifications"
    compliance="Must"
    cid="4015"
><![CDATA[<p>Agencies MUST use devices as shown in the following table for controlling the data flow of one-way gateways between networks of different classifications.</p><div align="center">
<table class="table-secondary" cellpadding="5">
<tbody>
<tr>
<td colspan="2">High network</td>
<td>Low network</td>
<td>You require</td>
</tr>
<tr>
<td rowspan="2">RESTRICTED</td>
<td class="table-cell-black" rowspan="2">&nbsp;</td>
<td>UNCLASSIFIED</td>
<td>EAL2 or PP diode</td>
</tr>
<tr>
<td>RESTRICTED</td>
<td>EAL2 or PP diode</td>
</tr>
<tr>
<td rowspan="3">CONFIDENTIAL</td>
<td class="table-cell-green" rowspan="3">&nbsp;</td>
<td>UNCLASSIFIED</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>RESTRICTED</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>CONFIDENTIAL</td>
<td>high assurance diode</td>
</tr>
<tr>
<td rowspan="4">SECRET</td>
<td class="table-cell-blue" rowspan="4">&nbsp;</td>
<td>UNCLASSIFIED</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>RESTRICTED</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>CONFIDENTIAL</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>SECRET</td>
<td>high assurance diode</td>
</tr>
<tr>
<td rowspan="5">TOP SECRET</td>
<td class="table-cell-red" rowspan="5">&nbsp;</td>
<td>UNCLASSIFIED</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>RESTRICTED</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>CONFIDENTIAL</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>SECRET</td>
<td>high assurance diode</td>
</tr>
<tr>
<td>TOP SECRET</td>
<td>high assurance diode</td>
</tr>
</tbody>
</table>
</div>]]></paragraph>
</block>
<block title="Diode assurance levels for NZEO networks"><paragraph
    title="19.4.5.R.01."

    tags="Technical,Gateway Security"


><![CDATA[<p>As NZEO networks are particularly sensitive additional security measures are necessary when connecting them to other networks.</p>]]></paragraph>
<paragraph
    title="19.4.5.C.01."

    tags="Technical,Gateway Security"


    classification="All Classifications"
    compliance="Must"
    cid="4028"
><![CDATA[<p>Agencies MUST use a diode of at least an EAL4 assurance level between an NZEO network and a foreign network in addition to the minimum assurance levels for diodes between networks of different classifications.</p>]]></paragraph>
<paragraph
    title="19.4.5.C.02."

    tags="Technical,Gateway Security"


    classification="All Classifications"
    compliance="Must"
    cid="4030"
><![CDATA[<p>In all other circumstances the table at <a href="http://nzism.gcsb.govt.nz/ism-document#Paragraph-16726">19.4.4.C.01</a> MUST apply.</p>]]></paragraph>
<paragraph
    title="19.4.5.C.03."

    tags="Technical,Gateway Security"


    classification="All Classifications"
    compliance="Should"
    cid="4032"
><![CDATA[<p>Agencies SHOULD use a diode of at least an EAL2 assurance level or a Protection Profile between an NZEO network and another New Zealand controlled network within a single security domain.</p>]]></paragraph>
</block>
<block title="Volume Checking"><paragraph
    title="19.4.6.R.01."

    tags="Technical,Gateway Security"


><![CDATA[<p>Monitoring the volume of data being transferred across a diode will ensure that it conforms to expectations.  It can also alert the agency to potential malicious activity if the volume of data suddenly changes from the norm.</p>]]></paragraph>
<paragraph
    title="19.4.6.C.01."

    tags="Technical,Gateway Security"


    classification="All Classifications"
    compliance="Should"
    cid="4039"
><![CDATA[<p>Agencies deploying a diode to control data flow within one-way gateways SHOULD monitor the volume of the data being transferred.</p>]]></paragraph>
</block>
</subsection>
</section>
