What is secure by design?
Secure by design is a security principle in which security is treated as a fundamental part of design, development, and architecture from the beginning. Rather than adding security controls after a system or product has been developed, security requirements and risks are considered throughout the development process.
Secure by design includes reducing the attack surface, limiting unnecessary privileges, protecting data and identities, and designing solutions so that security does not depend on users configuring every necessary security control themselves.
The principle also involves considering how a system could be attacked or misused while it is being designed. By identifying potential threats and weaknesses early, security can be incorporated into the architecture before the solution is deployed.
A useful analogy is planning the security of a building before construction begins. Entrances, access controls, fire protection, and other security measures are considered as part of the building’s design rather than attempting to address every security issue after construction is complete.
Sicra and secure by design
Secure by design is relevant for organizations developing, acquiring, or modernizing digital solutions. When security is considered early, risks can be addressed before weaknesses become embedded in the system architecture and persist throughout the solution’s lifecycle.
This requires security to be incorporated into decisions involving architecture, identities, access, networks, and cloud services. Threat modeling and risk assessments can also help identify how a solution could be attacked and which security controls should be implemented.
Sicra helps organizations with security strategy, security architecture, and assessments that enable security to be incorporated early in the development and modernization of digital solutions.
Services
Security strategy
Security maturity assessment
Sicra security analysis
Network architecture
CISO-for-hire
Related terms: Threat modeling, Attack surface, Zero Trust, Identity security, IAM (Identity and Access Management), Cybersecurity, Risk detection, Governance