An Overview of Secure by Design: Enhancing Systems Security through Systems Security Engineering and Threat Modeling

Demircioğu Murat, Ufuk Berkan, I.Mohammed Farook Ali · 2024

The main focus of system design and development is the performance and functionality of the system. Security related problems are usually an afterthought and are not factored into the system design and development processes. Penetration testing is the first answer that comes to mind when considering system security. Most of the time, these security tests are performed in a short period of time usually just before the system is released. Only the vulnerabilities that are found during the tests are fixed. The rest remain and are deployed with the systems. And more importantly, any flaw or vulnerability related with the core system design could not be detected with penetration tests. Any strategy based on patch management and penetration testing is not adequate enough to withstand complex cyber attacks. Secure by Design, Systems Security Engineering, and Threat Modeling are the essential pillars of building secure and cyber resilient systems. The proactive integration of security controls throughout the whole system development life cycle is emphasized by Secure by Design. Systems Security Engineering is a systems engineering discipline that adopts Secure by Design principles and offers a methodical way of developing secure systems. Threat modeling complements these methods by detecting potential threats and vulnerabilities early in the design phase to guide security countermeasures. This paper emphasizes how to combine these three techniques in order to improve a systems' security posture. It highlights the importance of continuous security maturity assessment and improvement throughout a system life cycle to handle new threats and vulnerabilities.

Read the paper · More papers on PaperTik