Secure by Design in 2024: prepare security before launch
Review defaults, access rights and exposed services before a website goes live.
Contents of this article
Security starts inside the product
CISA’s official bulletin records voluntary Secure by Design commitments from 68 software manufacturers on May 8, 2024. Reporting this event does not imply that WAFPRO is a signatory or holds a related certification.
Remove unsafe defaults before launch
Review test accounts, default passwords, debugging pages and unused components for both the public site and administration tools. Give operations, development and support staff the permissions their work needs instead of sharing one unrestricted account.
Combine edge protection with application fixes
SCDN and WAF can protect supported entry paths, while the application remains responsible for authorization and sensitive actions. Coordinate temporary rules, code fixes, regression testing and retirement of vulnerable versions.
Assign the checklist to people
Record asset, certificate and protection owners plus emergency contacts in the release checklist. Confirm those responsibilities whenever a new endpoint or subdomain is added.
References
CISA Community Bulletin, June 2024
