The field of Security-by-Design (SxD) is unintentionally influenced and curbed by two assumptions. First, the general view is that SxD is a purely technical field even though it involves significant legal, policy, governance, organisational and behavioural aspects besides its technical components. Second, a persistent fallacy exists that once the design of a system or application is secure from the start, its functioning should run perfectly. By supposing that malfunctioning is the result of a single point of failure, other vulnerabilities on a legal, policy, governance, technical, behavioural or organisational level are overlooked.
This project confronts both assumptions and aims to remove them by introducing a comprehensive methodology for SxD incorporating all relevant aspects related to legal, policy, governance, organisational, behavioural and technical views. Creating a common conceptual framework, the project aims to build a methodology for joining all aspects into a comprehensive SxD called Cyber Security by Integrated Design (C-SIDe). The developed methodology will be validated by means of a study on cyber security in private organisations and two case studies on specific technologies: high performance computing infrastructures in cloud environments and mobile application design. Additionally a study is conducted to find the most adequate institutional design for public governance to support integrated cyber security.
The approach by an interdisciplinary team of researchers and the involvement of public and private sector partners offers the project the wider angle that is needed to learn from good and bad experiences, to cover all potential points of failure as well as keeping the components of the cyber security ecosystem in an adequate balance with each other and with external factors.