EMZETT.
Login

Security by design

In short: Security by design means building security into the design of a system from the start instead of adding it later.

In more detail: Security gaps that sit in the architecture are expensive and hard to fix later. Anyone who thinks about it during planning saves effort and risk.

In Depth

Basic principles

  • Least privilege: every person and service gets only what it needs.
  • Defense in depth: several layers of protection so that a single gap is not enough.
  • Small attack surface: what is not there cannot be attacked. Leave out unneeded functions.
  • Fail secure: in case of error, access is denied, not allowed.
  • Data minimisation: data you do not store cannot be stolen.
  • Open methods: use proven encryption, do not invent your own.

Approach

  • Threat modelling: ask early who could attack what (e.g. with the STRIDE scheme).
  • Security in every phase: requirements, code reviews, tests, automated checks and updates.
  • Training of developers.

Complementary: security by default. For web applications see IT security in web development. Required by law, among others, by the Cyber Resilience Act.

See also: IT security, system architecture