Secure design principles are the rules of thumb that architects apply before any code is written or product chosen. The CISSP outline lists a set of them, including threat modeling, least privilege, defense in depth, secure defaults, fail securely, segregation of duties, keep it simple, zero trust, trust but verify, privacy by design, shared responsibility and secure access service edge (SASE). The exam expects you to recognize each from a description and to pick the principle that a design follows or violates.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.