Pattern: Safely Importing Data

Document preview7 pages
Cover of Pattern: Safely Importing Data
Page 1 of 7

Download this document free

Get this document with your free trial. Choose from the full Complyzard library.

Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.
Document information

An architecture pattern for safely importing data into a system from an external source.

Adapted edition

Document type
Reference Guide
Format
DOCX
Pages
7
Language
English
Version
1.0
Updated
2026-09-16
Description

An architecture pattern for safely importing data into a system from an external source for organisational planning, review and training. NCSC guidance is advisory and should be applied to the organisation's own risks and obligations.

Contents
  • Introduction
  • Structure
  • A. Defending attacks over the network
  • Nature of the attack
  • Defensive techniques
  • B. Avoiding the import of malicious content
  • Dealing with nested content
  • C. Recommended pattern for data import
  • Removing components
  • Important architectural considerations
  • D. Monitoring for attempted breaches
  • Monitoring the verification engine and the destination system
  • Monitoring the remaining components
  • External network connection
  • Transformation engine
  • Protocol break and flow control
  • Source links
Source and licence
Pattern: Safely Importing Data

National Cyber Security Centre

AttributionNational Cyber Security Centre, “Pattern: Safely Importing Data” (15 July 2018), reused under the Open Government Licence v3.0.

ChangesAdapted 16 September 2026: converted the official HTML article into neutral text-only DOCX and PDF editions. Preserved article headings, paragraphs, lists and plain-text source-link destinations; normalized web whitespace and typographic punctuation; omitted site navigation, topic and download cards, images, logos, scripts, styles and page furniture.

Version history
  • v1.016/09/2026
Report this document