DOE OSTI · 1970004
A National Secure-by-Design Strategy
Abstract
The US National Cybersecurity Strategy published March 2, 2023 uses plain language to communicate that the US is calling for a major change in how we prioritize the security of software systems used in critical infrastructure. It acknowledges that our current approach, which is essentially, “let the buyer beware,” leaves entities who are least able to assess or defend vulnerable software responsible for the impacts of designed-in weaknesses while the makers of the technology bear no liability. The strategy recommends a security-by-design approach, recommending that software vendors be held liable to uphold a “duty of care” to consumers and for systems to be designed to “fail safely and recover quickly” . For energy infrastructure, the strategy calls out the need to implement the National Cyber-Informed Engineering Strategy to achieve higher confidence security for energy infrastructures. The Idaho National Laboratory, a pioneer in cyber-informed engineering concepts, is at the forefront of organizations educating others in industry, academia, and government on how to apply these concepts to real-world challenges. In this brief, we'll outline some of the basic principles of security-by-design and offer examples of how, in a water sector context, they're being put into successful practice.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Wright, Virginia L, Bochman, Andrew A, Ohrt, Andrew. 2023-04-17. A National Secure-by-Design Strategy. https://www.osti.gov/biblio/1970004
Cite the original work for its findings. Save a collection to share your selection of sources.