- High Assurance Guard
A High Assurance Guard (HAG) is a
Multilevel security computer device which is used to communicate between differentSecurity Domains , such asNIPRNet toSIPRNet . The HAG is one example of aControlled Interface between security levels. HAGs are approved through theCommon Criteria process.Operation
The HAG runs a multiple hardware virtualization machine on separate processor - one subsystem for the lower classification, one subsystem of the higher classification. The hardware runs a type of
Knowledge Management software that examines traffic going from the higher classification side and rejects any traffic that is classified higher than the lower classification. In general, the HAG allows lower classified data that resides on a higher classified system, to be moved to another lower classified system. For example, in the US, it would allow unclassified information residing on a classified secret system to be moved to another unclassified system. Through various rules and filters, the HAG ensures that the data is of the lower classification and then allows the transfer.Importance, risks
The HAG is mostly used in email and DMS environments as certain organizations may only have unclassified network access, and they need to send a message to an organization that has only secret network access. The HAG provides them this ability.
Wikimedia Foundation. 2010.