Skip to Content
Secure Coding: Principles and Practices
book

Secure Coding: Principles and Practices

by Mark G. Graff, Kenneth R. van Wyk
June 2003
Intermediate to advanced
224 pages
6h 10m
English
O'Reilly Media, Inc.
Content preview from Secure Coding: Principles and Practices

2.2. Principles of Security Architecture

We've defined 30 basic principles of security architecture:

  1. Start by asking questions

  2. Select a destination before stepping on the gas

  3. Decide how much security is "just enough"

  4. Employ standard engineering techniques

  5. Identify your assumptions

  6. Engineer security in from day one

  7. Design with the enemy in mind

  8. Understand and respect the chain of trust

  9. Be stingy with privileges

  10. Test any proposed action against policy

  11. Build in appropriate levels of fault tolerance

  12. Address error-handling issues appropriately

  13. Degrade gracefully

  14. Fail safely

  15. Choose safe default actions and values

  16. Stay on the simple side

  17. Modularize thoroughly

  18. Don't rely on obfuscation

  19. Maintain minimal retained state

  20. Adopt practical measures users can live with

  21. Make sure some individual is accountable

  22. Self-limit program consumption of resources

  23. Make sure it's possible to reconstruct events

  24. Eliminate "weak links"

  25. Build in multiple layers of defense

  26. Treat an application as a holistic whole

  27. Reuse code known to be secure

  28. Don't rely on off-the-shelf software for security

  29. Don't let security needs overwhelm democratic principles

  30. Remember to ask, "What did I forget?"

The following sections define these principles in greater detail, and subsequent chapters explain them in the context of different phases of software development.

2.2.1. Start by Asking Questions

Whether you're starting from scratch with a clean sheet of paper or have been handed a complex piece of software that needs fixing or updating, your first step in ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Web Application Security

Web Application Security

Andrew Hoffman

Publisher Resources

ISBN: 0596002424Catalog PageErrata