Clause 5.3 — Product security by design
Subclause 5.3 defines the security by design principle in FprEN 40000-1-2:2026. Security measures must be integrated into products from the initial concept phase and maintained through the whole lifecycle.
What Clause 5.3 requires
Manufacturers must employ proven security architecture techniques, including:
- Least privilege: Restricting resource access to the absolute minimum necessary.
- Attack surface minimization: Removing unneeded interfaces, ports, and protocols.
- Defense in depth: Layering multiple security controls to eliminate single points of failure.
- Secure coding practices: Eliminating common software defects (memory safety, injection flaws) during implementation.
- No security by obscurity: Relying on robust mechanisms rather than hidden algorithms.
- User-centric design: Minimizing friction while preventing security circumvention.
How CVD Portal supports compliance
CVD Portal reinforces security by design principles across your product architecture and team workflows:
- Architecture and design artifact tracking: The platform technical file generator captures design decisions, trust boundaries, and interface protection controls.
- Automated dependency verification: Integrating with GitHub and SBOM registries ensures third-party libraries meet secure coding and maintenance criteria before integration.
- Policy library controls: Pre-formatted secure coding and architecture guidelines provide development teams with actionable compliance requirements.
- Audit trail proof: The platform records design reviews and control verification events in an immutable audit log for assessment bodies.