Security by design is an engineering approach in which security is treated as a foundational requirement and built into systems from the earliest stages rather than bolted on retrospectively. It favours secure defaults, minimal attack surface, defence in depth and least-privilege access, supported by threat modelling and continuous verification across the development lifecycle. The principle is increasingly mandated by regulators and procurement frameworks for connected products and critical infrastructure.
Overview
- Security by design is an engineering approach in which security is treated as a foundational requirement and built into systems from the earliest stages rather than added retrospectively.
- It favours secure defaults, minimal attack surface and continuous verification across the development lifecycle.
- The principle is increasingly mandated by regulators and procurement frameworks for critical systems.
Key aspects
- Threat modelling and risk assessment from requirements onward.
- Secure defaults and fail-safe configurations.
- Defence in depth and least-privilege access.
- Continuous testing, review and vulnerability management.
Applications
- Secure software development lifecycles in regulated industries.
- Design of Zero Trust Architecture network and identity systems.
- Hardening of connected products and critical infrastructure.