Pattern: Safely Importing Data
Download this document free
Get this document with your free trial. Choose from the full Complyzard library.
Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.Document information
An architecture pattern for safely importing data into a system from an external source.
Adapted edition
- Document type
- Reference Guide
- Format
- DOCX
- Pages
- 7
- Language
- English
- Version
- 1.0
- Updated
- 2026-09-16
- Category
- Privacy & data protection
- Licence
- Open Government Licence v3.0
Description
An architecture pattern for safely importing data into a system from an external source for organisational planning, review and training. NCSC guidance is advisory and should be applied to the organisation's own risks and obligations.
Contents
- Introduction
- Structure
- A. Defending attacks over the network
- Nature of the attack
- Defensive techniques
- B. Avoiding the import of malicious content
- Dealing with nested content
- C. Recommended pattern for data import
- Removing components
- Important architectural considerations
- D. Monitoring for attempted breaches
- Monitoring the verification engine and the destination system
- Monitoring the remaining components
- External network connection
- Transformation engine
- Protocol break and flow control
- Source links
Source and licence
National Cyber Security Centre
AttributionNational Cyber Security Centre, “Pattern: Safely Importing Data” (15 July 2018), reused under the Open Government Licence v3.0.
ChangesAdapted 16 September 2026: converted the official HTML article into neutral text-only DOCX and PDF editions. Preserved article headings, paragraphs, lists and plain-text source-link destinations; normalized web whitespace and typographic punctuation; omitted site navigation, topic and download cards, images, logos, scripts, styles and page furniture.
Version history
- v1.016/09/2026