THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



Security by Design necessitates identifying and meeting security requirements relevant to intended changes. Manual and ad-hoc approaches during an analysis cause overhead and delays. Precise requirements and definitions of done early on, including security-wise, are essential for better efficiency and put the focus on generating business value. Continuous integration, delivery and deployment solutions help from a development and operations point of view. Different teams may be responsible for fulfilling equivalent security requirements. Standard solutions for a particular set of requirements can help reduce waist: duplicate solutions for the same task. Governance depends on the enterprise and its context, which may affect how security is concretely built in. Enterprise goals shape requirements, applied controls and taken measures. This article details how Continuous Security by Design can help with these challenges.
Security modelling and assessment
The foundation for Continuous Security by Design is to separate general security aspects fulfilling enterprise goals from their concrete application. The former are represented in an enterprise security model. The latter only applies the model to concrete situations.
Governance and requirements
In a deterministic governance framework, equivalent non-functional, technology-agnostic security requirements apply for similar situations. Characteristics, such as information flows of a specific classification, represent everyday situations that require concrete requirements and can be determined via questions and answers. Rules perform risk-based threat modelling and can be applied to tailor requirements managed centrally.
Solutions
Enterprises have diverse application landscapes. Solutions in the form of application and service offerings have been designed to meet requirements. Mapping these solutions towards their requirements allows for the creation of a catalogue of solutions, indicating fulfilled requirements. Existing solutions for given requirements can be identified, which helps promote specific solutions. Evaluating the solution catalogue together with requirements that have been tailored allows us to identify gaps in the offering and fill them as per determined priorities.
“Continuous Security by Design takes a holistic point of view to support the generation of business value. By managing requirements and solutions end-to-end, efficiency is increased, teams are empowered, and the overall security posture is improved.”
Assessment and tailoring
Teams can answer questions regarding their product or intended change via a self-service assessment. Characteristics are identified, requirements are assigned, and immediate feedback is provided.
Requirement management
After teams have gathered requirements, they can manage them and check which solutions are available to satisfy them. They can use suitable offerings and focus on the remaining topics. When they implement a new solution for specific requirements and when it fits into the enterprise architecture, it can be added to the solution catalogue to save others time.
Using Continuous Security by Design
Continuous Security by Design supports activities in all software process models. Not only within development but also during maintenance, compliance with specific requirements must be ensured. Involved roles or triggers for assessments may vary. For example, system architects can do assessments based on new features. Time-boxed schedules benefit to a great degree, such as those used by Scrum or scaled agile methodologies. Non-functional requirements for features are more transparent, faster identified, and more likely to be fulfilled within one increment: unmet "must" requirements or security testing less frequently block deployments or require other risk management strategies to be applied.
Summary
Continuous Security by Design is based on an enterprise security model aligned with an enterprise's goals and governance and the application of the model in an automated way. It takes a holistic point of view and supports end-to-end, from requirements to their fulfilment. Efficiency is increased, teams are empowered, security solutions are better managed, and the overall security posture is improved.