Security by default
In short: Security by default means a product is already set up securely as delivered. Anyone who wants to make it less secure has to do so deliberately.
In more detail: Many users never change default settings. The default values must therefore be the secure choice.
In Depth
Examples of secure defaults
- There is no default password such as
admin/admin, a new password is mandatory on first start. - Unneeded services and ports are off (firewall closed).
- Connections are encrypted by default (HTTPS, WPA3).
- Accounts have as few rights as necessary (principle of least privilege).
- Automatic updates are on.
- Privacy-friendly default, that is collect only as much data as necessary (Art. 25 GDPR).
Distinction
Security by default concerns the default settings. Security by design concerns the design of the whole system. The two complement each other and appear, for example, in the Cyber Resilience Act.
See also: IT security, Cyber Resilience Act