kb:bestpractices:codingconventions:cybersecurity
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| kb:bestpractices:codingconventions:cybersecurity [2026/05/07 09:40] – joerg.hampel | kb:bestpractices:codingconventions:cybersecurity [2026/10/06 13:16] (current) – joerg.hampel | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== | + | ====== |
| - | + | ||
| - | //As the EU Cyber Resilience Act (CRA) *has already entered into force in 2024, and the first legal requirements must be fulfilled starting in September 2026, we are now explicitly collecting tips, tricks, and best practices related to the topic here.// | + | |
| + | <WRAP left round tip 60%> | ||
| + | **[[kb: | ||
| + | </ | ||
| ===== General Principles ===== | ===== General Principles ===== | ||
| Line 8: | Line 9: | ||
| * Treat all external input as untrusted | * Treat all external input as untrusted | ||
| * Prefer simple and explicit architectures | * Prefer simple and explicit architectures | ||
| - | * Fail safely and log security-relevant failures | + | * Fail safely and log security-relevant failures |
| - | * Minimize attack surface | + | * Minimize |
| - | * Apply the principle of least privilege | + | * Keep third-party |
| + | * Apply the principle of least privilege | ||
| + | * Do not reinvent the wheel (use existing encryption algorithms etc) | ||
| + | * Review security implications during code reviews and design reviews, not only during testing | ||
| ===== Secrets and Credentials ===== | ===== Secrets and Credentials ===== | ||
| + | * Choose secure defaults | ||
| * Never hardcode: | * Never hardcode: | ||
| * passwords | * passwords | ||
| Line 27: | Line 32: | ||
| * source-controlled config files | * source-controlled config files | ||
| * Do not log sensitive information | * Do not log sensitive information | ||
| + | * Solutions | ||
| + | * " | ||
| + | * Better: Store secrets in a place the regular user cannot access | ||
| ===== Networking ===== | ===== Networking ===== | ||
| Line 32: | Line 40: | ||
| * Prefer encrypted communication (TLS, HTTPS, SSH) | * Prefer encrypted communication (TLS, HTTPS, SSH) | ||
| * Avoid plaintext credentials and insecure protocols | * Avoid plaintext credentials and insecure protocols | ||
| - | * Validate | + | * Validate remote peers (eg using certificates) |
| + | * restrict access on a network level (IP ranges etc) | ||
| + | * Use existing protocols | ||
| * Explicitly document: | * Explicitly document: | ||
| * timeout behavior | * timeout behavior | ||
| Line 104: | Line 114: | ||
| * Prefer signed installers and executables | * Prefer signed installers and executables | ||
| + | |||
| + | ===== Resources ===== | ||
| + | |||
| + | * [[kb: | ||
| + | |||
| + | |||
| + | ---- | ||
| + | |||
| + | <block 100%: | ||
| + | A set of guidelines that recommend programming style, better practices, and methods for all our LabVIEW projects. We ask all our peers to follow these guidelines to help improve the readability of our shared source code and make software maintenance easier.</ | ||
| + | |||
| + | |< 100% 50% >| | ||
| + | |[[kb: | ||
kb/bestpractices/codingconventions/cybersecurity.1778146857.txt.gz · Last modified: 2026/05/07 09:40 by joerg.hampel