Security by design
In short: Security by design means building security into the design of a system from the start instead of adding it later.
In more detail: Security gaps that sit in the architecture are expensive and hard to fix later. Anyone who thinks about it during planning saves effort and risk.
In Depth
Basic principles
- Least privilege: every person and service gets only what it needs.
- Defense in depth: several layers of protection so that a single gap is not enough.
- Small attack surface: what is not there cannot be attacked. Leave out unneeded functions.
- Fail secure: in case of error, access is denied, not allowed.
- Data minimisation: data you do not store cannot be stolen.
- Open methods: use proven encryption, do not invent your own.
Approach
- Threat modelling: ask early who could attack what (e.g. with the STRIDE scheme).
- Security in every phase: requirements, code reviews, tests, automated checks and updates.
- Training of developers.
Complementary: security by default. For web applications see IT security in web development. Required by law, among others, by the Cyber Resilience Act.
See also: IT security, system architecture