enisaeu GitHub avatar

enisa-sbd-playbook

enisaeu

一套实用的22个安全设计及默认安全行动手册,包含结构化检查清单,帮助中小企业在产品开发及默认配置中嵌入安全措施。

Stars

10

7 天增长

暂无数据

Fork 数

3

开放 Issue

0

开源协议

CC-BY-4.0

最近更新

2026-07-30

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

它将ENISA的高层安全原则转化为具体、可操作的检查清单,并提供渐进式采用指导,覆盖从设计到报废的整个产品生命周期。

适合谁使用

  • 中小企业软件开发者与工程师
  • 技术产品经理
  • 中小企业安全负责人
  • 系统架构师

典型使用场景

  • 从产品开发初期嵌入安全措施
  • 建立产品安全的工程基线
  • 为满足欧盟网络弹性法案等合规要求做准备
  • 减少重复性漏洞并改进事件响应能力

项目优势

  • 提供22个可直接应用的行动手册,每个包含检查清单、最低证据和发布门禁
  • 基于欧盟权威网络安全机构ENISA,具有公信力
  • 提出渐进式采用框架,让中小企业能按优先级逐步加强安全实践
  • 涵盖安全设计(架构与运营)和默认安全(加固与引导保护)两大方面

使用前须知

  • 明确表示为实践起点,而非穷尽性实施框架
  • 不提供法律指导,需要根据具体产品情境和风险进行调整
  • 行动手册较为通用,对大型企业或高度专业化产品可能需要大量定制

README 快速开始

ENISA Secure by Design and Default Playbooks

A practical collection of 22 Secure by Design and Secure by Default playbooks for SMEs, based on the ENISA Secure by Design and Default Playbook: A Practical Guide to Secure by Design and Default for SMEs.

About

Secure by Design represents a fundamental shift in product security, embedding protective measures from conception rather than retrofitting them post-development. Secure by Default ensures products ship with the most secure configuration reasonably possible, reducing reliance on user expertise and limiting the potential for misconfiguration.

This repository provides a list of playbooks that aims to bridge the gap between aspirational security principles and practical implementation within SME constraints. It provides structured, easy-to-follow checklists that development teams can apply during design, build, deployment, maintenance, and decommissioning.

The guidance is intended as a practical starting point rather than an exhaustive or prescriptive implementation framework. Its application should be adapted to the product’s intended use, context and associated risks, as well as applicable requirements. It does not provide legal guidance.

Playbook structure

Each playbook contains:

  • Principle
  • Objective
  • Checklist
  • Minimum evidence
  • Release gate

Playbooks

Secure by Design

Secure by Design embeds protective measures into products during development, rather than adding them retrospectively.

  • Architectural Foundations — structural design choices that make a product inherently difficult to compromise or exploit.
  • Operational Integrity — human and procedural practices that maintain product security throughout development, deployment, operation, and retirement.
Architectural FoundationsOperational Integrity
Trust boundaries and threat modellingLeast privilegeStrong identity and authentication architectureAttack surface minimisationDefence in depthOpen designLife-cycle management• [User-centric design](playbooks/08-user-centric

项目描述

A practical collection of Secure by Design and Secure by Default playbooks for SMEs, based on the ENISA Secure by Design and Default Playbook.

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

slvDev
精选
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI 与机器学习大语言模型
1,960
jamesob
精选
jamesob GitHub avatar

local-llm

A comprehensive guide for building and configuring a high-end local machine to run state-of-the-art LLMs, with detailed hardware choices, BIOS tuning, and Docker-based model serving.

AI 与机器学习大语言模型
1,660
makecindy
精选
makecindy GitHub avatar

cindy

Cindy is an open-source AI agent that runs locally on your machine, integrates multiple AI harnesses and models, and provides memory, skills, and automation to perform real work in your projects and apps.

AI 与机器学习大语言模型
958