The principle of security by design integrates security at the early stages of a project, where it is cheapest to build and most effective. The Cyber Resilience Act makes it a legal expectation for every product with digital elements.
In this course, you learn how to embed security into your existing processes at every stage of a product’s lifecycle: from its conception, through deployment and operation, until its end of life. You learn about the requirements at the early stages of a project, and discover how to use security assurance mechanisms throughout the development process. For every stage, you identify the roles, responsibilities and accountabilities around security.
This course is tailored to your internal processes: we work from your development lifecycle, your tools and your release gates, not from a generic model.
Audience: this course is ideal for product owners, engineering teams, software and firmware developers, IoT manufacturers and technical experts outside security. It is also built for security experts who want to support project and product development.
You study a real-life case where security by design helped an IoT manufacturer save several million euros while developing a system that integrates third parties and several technologies: devices, mobile applications and cloud.
Objectives
-
Understand the issues behind the current state of product security.
-
Understand the principles of security by design and the benefits of a security by default approach.
-
Define security requirements at project start.
-
Organise security: the importance of coordination and communication around the security functions, with clear roles and accountabilities.
-
Manage security throughout product development, and validate it with security assurance mechanisms.
Programme
-
High-profile attacks against IoT systems, and how the lack of security by design led to vulnerabilities that affected a product and the reputation of a company.
-
Security by design and security by default: definitions.
-
How security usually integrates into the lifecycle of a project, supply chain included.
-
Managing security throughout product development: requirements, responsibilities and accountabilities, coordination and communication.
-
Validation through security assurance.
