Secure by Design in 2024: prepare security before launch

Review defaults, access rights and exposed services before a website goes live.

Contents of this article

Security starts inside the product

CISA’s official bulletin records voluntary Secure by Design commitments from 68 software manufacturers on May 8, 2024. Reporting this event does not imply that WAFPRO is a signatory or holds a related certification.

Remove unsafe defaults before launch

Review test accounts, default passwords, debugging pages and unused components for both the public site and administration tools. Give operations, development and support staff the permissions their work needs instead of sharing one unrestricted account.

Combine edge protection with application fixes

SCDN and WAF can protect supported entry paths, while the application remains responsible for authorization and sensitive actions. Coordinate temporary rules, code fixes, regression testing and retirement of vulnerable versions.

Assign the checklist to people

Record asset, certificate and protection owners plus emergency contacts in the release checklist. Confirm those responsibilities whenever a new endpoint or subdomain is added.

References

CISA Community Bulletin, June 2024

Related products and onboarding

View products and onboarding information

Back to industry insights Contact technical support