Secure by Design: A Guide for Manufacturers (CISA)
Secure by default tactics: product configuration practices – Secure by Design: A Guide for Manufacturers (CISA)

Secure by Design: A Guide for Manufacturers (CISA) DF-5: Software authorization profiles

Recommend authorisation roles and the use case each is designed for, and show a visible warning of increased risk when customers depart from the recommended profile; a doctor seeing all patient records while a scheduler sees only what booking requires is the example.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Secure by default tactics: product configuration practices – Secure by Design: A Guide for Manufacturers (CISA)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.