enisaeu GitHub avatar

enisa-sbd-playbook

enisaeu

A practical collection of 22 Secure by Design and Secure by Default playbooks with structured checklists, designed to help SMEs embed security into product development and default configurations.

Stars

8

7-day growth

No data

Forks

3

Open issues

0

License

CC-BY-4.0

Last updated

2026-07-30

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

It translates ENISA's high-level security principles into concrete, actionable checklists for SMEs, offering progressive adoption guidance and covering the full product lifecycle from design to decommissioning.

Who it is for

  • Software developers and engineers at SMEs
  • Technical product managers
  • SME security leads
  • System architects

Use cases

  • Embedding security from the start of product development
  • Establishing a foundational engineering baseline for secure products
  • Preparing for regulatory compliance (e.g., EU Cyber Resilience Act)
  • Reducing recurring vulnerabilities and improving incident response

Strengths

  • Provides 22 directly actionable playbooks each with a checklist, minimum evidence, and release gate
  • Based on ENISA, a reputable EU cybersecurity agency, lending authority
  • Offers a progressive adoption framework so SMEs can prioritise and scale security efforts over time
  • Covers both Secure by Design (architectural and operational) and Secure by Default (hardening and guided protection)

Considerations

  • Explicitly stated as a practical starting point, not an exhaustive implementation framework
  • Does not provide legal guidance and may need adaptation to specific product contexts and risks
  • The playbooks are generic and may require significant tailoring for larger enterprises or highly specialised products

README quick start

ENISA Secure by Design and Default Playbooks

A practical collection of 22 Secure by Design and Secure by Default playbooks for SMEs, based on the ENISA Secure by Design and Default Playbook: A Practical Guide to Secure by Design and Default for SMEs.

About

Secure by Design represents a fundamental shift in product security, embedding protective measures from conception rather than retrofitting them post-development. Secure by Default ensures products ship with the most secure configuration reasonably possible, reducing reliance on user expertise and limiting the potential for misconfiguration.

This repository provides a list of playbooks that aims to bridge the gap between aspirational security principles and practical implementation within SME constraints. It provides structured, easy-to-follow checklists that development teams can apply during design, build, deployment, maintenance, and decommissioning.

The guidance is intended as a practical starting point rather than an exhaustive or prescriptive implementation framework. Its application should be adapted to the product’s intended use, context and associated risks, as well as applicable requirements. It does not provide legal guidance.

Playbook structure

Each playbook contains:

  • Principle
  • Objective
  • Checklist
  • Minimum evidence
  • Release gate

Playbooks

Secure by Design

Secure by Design embeds protective measures into products during development, rather than adding them retrospectively.

  • Architectural Foundations — structural design choices that make a product inherently difficult to compromise or exploit.
  • Operational Integrity — human and procedural practices that maintain product security throughout development, deployment, operation, and retirement.
Architectural FoundationsOperational Integrity
Trust boundaries and threat modellingLeast privilegeStrong identity and authentication architectureAttack surface minimisationDefence in depthOpen designLife-cycle management• [User-centric design](playbooks/08-user-centric

Description

A practical collection of Secure by Design and Secure by Default playbooks for SMEs, based on the ENISA Secure by Design and Default Playbook.

Related repositories

Similar projects matched by category, topics, and programming language.

slvDev
Featured
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI & Machine LearningLarge Language Models
1,960
jamesob
Featured
jamesob GitHub avatar

local-llm

A comprehensive guide for building and configuring a high-end local machine to run state-of-the-art LLMs, with detailed hardware choices, BIOS tuning, and Docker-based model serving.

AI & Machine LearningLarge Language Models
1,660
makecindy
Featured
makecindy GitHub avatar

cindy

Cindy is an open-source AI agent that runs locally on your machine, integrates multiple AI harnesses and models, and provides memory, skills, and automation to perform real work in your projects and apps.

AI & Machine LearningLarge Language Models
958