Tag

Secure By Design

All articles tagged with #secure by design

"CISA and NSA Unveil Top Cybersecurity Misconfigurations Threatening US Security"
cybersecurity2 years ago

"CISA and NSA Unveil Top Cybersecurity Misconfigurations Threatening US Security"

The US Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have identified unchanged default credentials as the top cybersecurity misconfiguration that leads to cyberattacks. The agencies' top ten major cybersecurity misconfigurations also include improper separation of user and admin privileges and insufficient network monitoring. The cybersecurity advisory (CSA) released by CISA aims to encourage software manufacturers to adopt secure-by-design and secure-by-default principles throughout the development cycle. The CSA highlights the importance of addressing systemic weaknesses in organizations and emphasizes the need for software manufacturers to reduce the burden on network defenders.

cybersecurity3 years ago

"Push for Secure Software: U.S. and International Partners Publish Guidelines"

The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI, NSA, and cybersecurity authorities of several countries, have published joint guidance urging software manufacturers to prioritize secure-by-design and -default products. The guidance outlines core principles to guide software manufacturers in building software security into their design processes prior to developing, configuring, and shipping their products. The goal is to create a future where technology and associated products are safe for customers. The guidance is the first of its kind and is intended to catalyze progress toward further investments and cultural shifts necessary to achieve a safe and secure future.

cybersecurity3 years ago

Global push for secure-by-design software guidelines

Technology providers must prioritize security at the executive level to ensure their products are both secure by design and secure by default. Secure by Design principles should be implemented during the product development lifecycle to reduce exploitable flaws, while Secure by Default products are secure to use out of the box with little to no configuration changes.