What is Security and Privacy by Design?

What is Security and Privacy by Design?

IBM defines Security and Privacy by Design (SPbD) as a streamlined and agile set of focused security and privacy practices. SPbD is aligned with the United States National Institute of Standards and Technology (NIST’s) Secure Software Development Framework (SSDF).

Security and Privacy by Design is made up of six (6) components:

  1. Threat model
  2. Privacy Assessment
  3. Vulnerability Management
  4. Secure Release Process
  5. Code Scan
  6. Penetration Test

Security and Privacy by Design reinforces IBM's commitment to security and privacy by embedding security and privacy into the design of IBM products and services including successful validation of Secure Release criteria prior to product ship.



To view or add a comment, sign in

Others also viewed

Explore topics