kb:bestpractices:codingconventions:cybersecurity
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| kb:bestpractices:codingconventions:cybersecurity [2026/06/25 10:11] – joerg.hampel | kb:bestpractices:codingconventions:cybersecurity [2026/10/06 13:16] (current) – joerg.hampel | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== | + | ====== |
| <WRAP left round tip 60%> | <WRAP left round tip 60%> | ||
| - | [[kb: | + | **[[kb: |
| </ | </ | ||
| Line 10: | Line 10: | ||
| * Prefer simple and explicit architectures | * Prefer simple and explicit architectures | ||
| * Fail safely and log security-relevant failures (log level WARNING) | * Fail safely and log security-relevant failures (log level WARNING) | ||
| - | * Minimize attack surface | + | * Minimize |
| + | * Keep third-party | ||
| * Apply the principle of least privilege (both when developing and in the final product) | * Apply the principle of least privilege (both when developing and in the final product) | ||
| * Do not reinvent the wheel (use existing encryption algorithms etc) | * Do not reinvent the wheel (use existing encryption algorithms etc) | ||
| - | + | * Review security implications during code reviews and design reviews, not only during testing | |
| ===== Secrets and Credentials ===== | ===== Secrets and Credentials ===== | ||
| + | * Choose secure defaults | ||
| * Never hardcode: | * Never hardcode: | ||
| * passwords | * passwords | ||
| Line 123: | Line 126: | ||
| |< 100% 50% >| | |< 100% 50% >| | ||
| - | |[[kb: | + | |[[kb: |
kb/bestpractices/codingconventions/cybersecurity.1782382271.txt.gz · Last modified: 2026/06/25 10:11 by joerg.hampel