Know the basics

Understand Secure by Design across Defence.

What is Secure by Design

How capability teams can take a collective approach to cyber security.

Who is responsible for Secure by Design

Cyber security is everyone’s responsibility.

Why we use Secure by Design

Understand the importance of adopting secure by design.

Applying Secure by Design

How to build security into your capability from the start.


Be secure

Check what you need to do for each principle and use existing tools.

Understand and define context

Understand what your capability does and how it uses and manages data.

Plan the security activities

Plan the right security activities including assessment of cyber threat and potential risks.

Implement continuous risk management

Make cyber security risk management a continuous process.

Define security controls

Set up security controls or use current services and patterns.

Engage and manage the supply chain

Understand your supply chain, including risks and security.

Assure, verify and test

Understand how to get security assurance, testing and validation throughout your capability’s lifecycle.

Plan the through-life approach

Continuously monitor for through-life security improvements.


Keep in touch

Find further resources and tell us what’s missing.

CySAAS services

Find more about the Cyber Security Assessment and Advisory Services (CySAAS) team.

Give feedback

Tell us what you think and if any guidance is missing.