OpenSSF Finding and Fixing Vulnerabilities Using AI

6.3 Apply secure by design and secure by default

Only trying to find and fix software vulnerabilities one at a time will not succeed in the long term. It’s necessary, but future changes might re-introduce other vulnerabilities. So, also apply the general principles of secure-by-design and secure-by-default.

As always, if a system is to be secure in the real world, it must be:

Secure-by-design and secure-by-default “must become standard practice – not an aspiration” [FiveEyes2026].

Quiz

Q1. What does “secure-by-default” mean, per the material?

  1. Security features exist but must be manually enabled after reading a guide
  2. The software is secure in its default installation, without extra hardening steps
  3. The software’s entire source code is kept fully confidential
  4. The software updates itself automatically, without any user consent
Show answer Answer: B