Upgrade 2024: Let's Upgrade Reality
April 11, 2024 // Upgrade 2024
Why Service Providers Should Align to “Secure by Default” Versus “Secure by Design”
Summary
Why service providers should align to “secure by default” versus “secure by design”
This session focuses on the increasing complexity of systems and software, accompanied by growing sophistication among attackers, that make it challenging for technology implementors and security teams to ensure secure outcomes. It emphasizes the importance of “secure by default” principles, where software and systems are designed with security as the default configuration, and requires extra effort to make them less secure (the customer would need to purposely downgrade security capabilities which are enabled by default, i.e. multi-factor authentication). Furthermore, it contrasts “secure by default” with “secure by design,” “securable,” “unmanaged,” and “insecure by default” systems. Examples from various platforms, like Amazon S3 and React, illustrate how secure by default principles can be implemented effectively. There is an emphasis on the need for collaboration among security teams, user experience designers, product managers, and engineers to prioritize secure by default approaches. Lastly, the talk highlights the Critical SaaS Special Interest Group (CSaaS SIG) as a forum for collaboration and intelligence sharing among SaaS companies to improve security outcomes.