User Tools

Site Tools


kb:bestpractices:codingconventions:cybersecurity

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
kb:bestpractices:codingconventions:cybersecurity [2026/06/25 09:58] – joerg.hampelkb:bestpractices:codingconventions:cybersecurity [2026/10/06 13:16] (current) – joerg.hampel
Line 1: Line 1:
-====== 08 Cybersecurity ====== +====== 09 Cybersecurity ======
- +
-//As the EU Cyber Resilience Act (CRA) has already entered into force in 2024, and the first legal requirements must be fulfilled starting in September 2026, we are now explicitly collecting tips, tricks, and best practices related to the topic here.//+
  
 +<WRAP left round tip 60%>
 +**[[kb:bestpractices:wow:methodology#security_by_design|Security by Design]] is one of the guiding principles here at HSE.**
 +</WRAP>
  
 ===== General Principles ===== ===== General Principles =====
Line 9: Line 10:
   * Prefer simple and explicit architectures   * Prefer simple and explicit architectures
   * Fail safely and log security-relevant failures (log level WARNING)   * Fail safely and log security-relevant failures (log level WARNING)
-  * Minimize attack surface and unnecessary dependencies+  * Minimize the attack surface by exposing only the functionality that is actually required 
 +  * Keep third-party dependencies as few as possible and up to date
   * Apply the principle of least privilege (both when developing and in the final product)   * Apply the principle of least privilege (both when developing and in the final product)
   * Do not reinvent the wheel (use existing encryption algorithms etc)   * Do not reinvent the wheel (use existing encryption algorithms etc)
- +  * Review security implications during code reviews and design reviews, not only during testing 
 ===== Secrets and Credentials ===== ===== Secrets and Credentials =====
  
 +  * Choose secure defaults
   * Never hardcode:   * Never hardcode:
     * passwords     * passwords
Line 110: Line 114:
   * Prefer signed installers and executables   * Prefer signed installers and executables
  
 +
 +===== Resources =====
 +
 +  * [[kb:cs:cra|EU Cyber Resilience Act (CRA)]]
 +
 +
 +---- 
 +
 +<block 100%:0:#FFF8FF;#800080;1px dotted #800080;Arial, Helvetica, sans-serif/10ptrounded>**[[https://createbettersoftware.com|The HSE Way of Working]]:** \\ 
 +A set of guidelines that recommend programming style, better practices, and methods for all our LabVIEW projects. We ask all our peers to follow these guidelines to help improve the readability of our shared source code and make software maintenance easier.</block>
 +
 +|< 100% 50% >|
 +|[[kb:bestpractices:codingconventions:database|<< 08 Databases]]  |  [[kb:bestpractices:codingconventions:sharedlibraries|11 Shared Libraries (DLLs) >>]]|
  
kb/bestpractices/codingconventions/cybersecurity.1782381535.txt.gz · Last modified: 2026/06/25 09:58 by joerg.hampel