Developer Proposes 3D/4D Framework to Separate Secure Design from Secure Delivery
A software security practitioner has outlined a structured model distinguishing between designing a secure system and proving that the implementation actually meets those security goals. The proposed '3D Method' involves three steps: representing the intended system architecture, defining its security objectives through threat modelling or risk assessment, and determining the controls needed to meet those objectives. A fourth optional step, 'Demonstrate,' extends the framework into what the author calls secure delivery, covering control validation, architectural conformance, and security testing. The author argues this separation becomes increasingly important as AI-assisted development grows, since AI-generated code may diverge from the original architectural intent without a formal verification step. The piece invites community feedback on whether demonstration should be considered an integral part of Secure by Design or treated as a distinct follow-on process.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in