infodas Data-Centric Security
(DCS).
Data-Centric Security places the data itself at the center of the security architecture. Especially in networked and interoperable environments, controlled and trustworthy data access is becoming a key factor for secure collaboration across security domains. Organizations are developing their architecture in stages — from clear data classification and policy-based access control to cryptographically protected data.
Cross-Domain Solutions (CDS) form the cornerstone of this architecture, ensuring that data-centric security policies are enforced and validated whenever information is transferred between security domains.
infodas. Driving Secure Data Sharing with Data-Centric Security.
infodas.
Enabling secure information sharing through Data-Centric Security.
Secure data.
Trusted collaboration.
Mission success.
Powered by infodas.
Get in touch with our DCS experts.
NATO Data-Centric Security Maturity Model.
A Structured Path to Secure Information Sharing Across NATO and Allied Operations.
The NATO Data-Centric Security (DCS) Maturity Model, defined within ACP-240, provides a strategic framework for protecting information throughout its entire lifecycle. As a key component of NATO’s Data Strategy and Digital Transformation Implementation Strategy, the model enables organizations to move beyond traditional perimeter-based security and adopt a modern, data-centric approach to information protection.
The DCS Maturity Model establishes a clear evolutionary path toward secure, interoperable, and policy-driven information sharing across multi-domain operations, coalition environments, and federated digital ecosystems.
Its core principle is simple: protect data at its source and maintain control over it wherever it travels.
DCS-1: Basic Labelling.
Establishing Data Awareness and Control
The first maturity level focuses on ensuring that all newly created information is properly labelled with mandatory handling instructions. These labels provide the foundation for all subsequent Data-Centric Security capabilities.
Organizations implementing DCS-1 assign standardized metadata to data objects, including security classifications, releasability markings, and handling caveats. This creates a consistent understanding of how information must be protected and shared.
Based on NATO STANAG 4774, DCS-1 introduces standardized confidentiality metadata labels that can be interpreted and enforced across systems and organizational boundaries.
Key Capabilities:
- Mandatory data classification and releasability labelling
- Standardized confidentiality metadata according to STANAG 4774
- Automated identification of unlabeled information
- Quarantine and reporting of non-compliant data
- Foundation for interoperable information sharing
Business Value:
DCS-1 creates visibility, accountability, and governance for mission-critical information while establishing the baseline for future Data-Centric Security capabilities.
DCS-2: Enhanced Labelling and Access Control.
Enforcing Policy-Based Access Decisions
At the second maturity level, organizations move beyond simple data classification and begin enforcing access decisions directly based on metadata and user attributes.
This stage introduces Attribute-Based Access Control (ABAC) through Confidentiality Metadata-Based Access Control (CMBAC). Access requests are evaluated by comparing the security attributes of a user, device, or process against the metadata attached to the requested information.
Instead of relying solely on network location or predefined trust zones, access is dynamically granted based on policy-driven security decisions.
The implementation of DCS-2 is supported through the eXtensible Markup Language Security Policy Information File (XMLSPIF), enabling standardized policy exchange and enforcement across organizations.
Key Capabilities:
- Attribute-Based Access Control (ABAC)
- Confidentiality Metadata-Based Access Control (CMBAC)
- Dynamic authorization decisions based on security attributes
- Policy-driven access enforcement
- XMLSPIF-based security policy management
- Improved interoperability across coalition environments
Business Value:
DCS-2 enables organizations to securely share information while maintaining fine-grained control over who can access specific data, under which conditions, and for which mission purposes.
DCS-3: Cryptographic Protection.
Protecting Data Beyond the Perimeter
The highest maturity level introduces persistent cryptographic protection directly at the data layer.
At DCS-3, information is transformed into secure, encrypted Data-Centric Security objects. Security metadata is cryptographically bound to the data, and content is protected through end-to-end encryption and digital signing mechanisms.
This approach ensures that information remains protected even when traditional security controls fail. If network boundaries are bypassed, devices are compromised, or files are copied to unauthorized locations, the data remains inaccessible to unauthorized users.
Key Capabilities:
- End-to-end encryption
- Cryptographic metadata binding
- Digital signing and integrity protection
- Persistent protection throughout the data lifecycle
- Secure data exchange across domains and organizations
- Protection independent of infrastructure or network boundaries
Business Value:
DCS-3 delivers the highest level of information assurance by ensuring that security remains attached to the data itself, regardless of where it travels or how it is accessed.
Supporting NATO’s Digital Transformation.
The NATO Data-Centric Security Maturity Model is a foundational element of the Alliance’s transition toward a secure, federated digital ecosystem.
By implementing DCS capabilities, organizations can move from isolated and static information environments toward dynamic, interoperable architectures that support secure collaboration across military commands, government agencies, coalition partners, and mission networks. This transformation enables a shift from restrictive “need-to-know” models toward secure “need-to-share” information exchange, improving operational effectiveness while maintaining robust information protection.
How infodas supports DCS implementation.
infodas supports organizations transitioning to Zero Trust and Data-Centric Security architectures by enforcing security policies at domain boundaries. Its solutions validate classification-aware security labels, enable assisted metadata tagging, and ensure data protection during cross-domain information exchange.
Frequently asked questions about DCS.
Open questions?
Contact our experts to schedule a personal consultation.
News.
Operational effectiveness increasingly depends on trusted data. During a joint congress organized by AFCEA Europe, infodas and with support from leading companies, representatives from NATO,…
Cologne. infodas introduces the SDoT COMP-LAND TE, a cross-domain solution for secure data exchange at the tactical edge. As armed forces accelerate the digitalization of…
infodas and Habilito have formed a strategic partnership to advance cross-domain solutions in Finland for government and security-critical environments. The partnership combines infodas’ field proven…
Cybersecurity is not just a line in IT budgets. In a hyperconnected, VUCA world, where classic forecasting is insufficient. This article sketches how strategic foresight,…
infodas and Mattermost are joining forces to support NATO and its partner nations in achieving a decision advantage in Multi-Domain Operations (MDO). They enable coalition…
Let’s get in touch!
Contact our cybersecurity experts. Together we will find a customized solution to protect your highly sensitive data.