Skip to main content

Core / Ccc / Controls / v2025.10

Restrict Data Replication to Trust Perimeter

CCC.Core.CN10 · Data Resilience

Ensure that data is only replicated on infrastructure in locations that are explicitly included within a defined trust perimeter.

Related Capabilities

IDTitleDescription
CCC.Core.CP21Resource ReplicationThe service may be configured to replicate child resources across multiple deployments.

Related Threats

IDTitleDescription
CCC.Core.TH04Data is Replicated to Untrusted or External LocationsSystems are susceptible to unauthorized access or interception by actors with political or physical control over the network in which they are deployed. Confidentiality may be impacted if the data is replicated to a network where the geopolitical status is untrusted, unstable, or insecure.

Assessment Requirements

IDTextApplicability
CCC.Core.CN10.AR01When data is replicated, the service MUST ensure that replication only occurs to destinations that are explicitly included within the defined trust perimeter.tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
CCMDSP-10Sensitive Data Transfer (only processed within scope as permitted)
CCMDSP-19Data Location (specify and document the physical locations of data)