Skip to content

Secure by Design

What is Secure by Design?

An approach to product development that integrates security considerations from the earliest design phases rather than adding them after development.

Information Security

Each of these is named in at least one of the same controls as secure by design. The number is how many controls name both.

What the standards actually require on secure by design

Requirements naming secure by design across 6 standards, quoted from the control text.

Secure by Design principles and practices are followed throughout the software development life cycle.

ISM-0401 · Secure by Design principles and practices are followed throughout the software development

Publicly sign the CISA Secure by Design Pledge and report progress against the seven goals.

SBD-20 · Sign the Secure by Design Pledge
IEC 624431 control

Product supplier applies secure-by-design principles including defence in depth, least privilege, secure default configurations, security architecture review and attack surface minimisation.

62443-4-1-SD · Secure by Design

Article 8 imposes security obligations on the National Cyber Hubs and Cross-Border Cyber Hubs as integral parts of the Alert System: technical and organisational measures to ensure confidentiality, integrity and availability of the Hub infrastructure and the d...

CSA-Art.8 · Security of the Alert System (Article 8)

Operate OT supply chain + asset lifecycle + physical security per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7. OT Supply Chain Security must (a) qualify OT vendors and suppliers per NIST SP 800-161 Supply Chain Risk Management tailored to OT (vendor cybersecuri...

NISTSP82-8 · OT Supply Chain Security, Asset Lifecycle, and Physical Security

Questions people ask about secure by design

What is Secure by Design?
An approach to product development that integrates security considerations from the earliest design phases rather than adding them after development.
Why is Secure by Design important for compliance?
Secure by Design is a key concept in Information Security. Understanding secure by design helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Secure by Design?
Secure by Design appears in the requirement text of Australian Information Security Manual, Secure by Design: A Guide for Manufacturers (CISA), IEC 62443, EU Cyber Solidarity Act (Regulation (EU) 2025/38), IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2). Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Secure by Design?
Explore our compliance framework pages to see how secure by design applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Secure by Design applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.