microsoft

secure-by-design

Secure by Design principles knowledge base for assessing security-first design, development, and deployment across the software lifecycle.

microsoft 1,367 270 Updated 2mo ago

Resources

1
GitHub

Install

npx skillscat add microsoft/hve-core/secure-by-design

Install via the SkillsCat registry.

About this skill

This skill provides a structured knowledge base of Secure by Design principles from UK and Australian government sources, enabling assessment of security practices across the software lifecycle. It helps identify gaps in security-first design, development, and deployment processes. Developers and agents should use it when evaluating or improving software security adherence from initial design through continuous operation.

SKILL.md

Secure by Design — Skill Entry

This SKILL.md is the entrypoint for the Secure by Design skill.

The skill synthesizes the UK Government Secure by Design Principles (10 principles) and the
Australian ASD/ACSC Secure by Design Foundations (6 foundations) into structured,
machine-readable references that an agent can query to identify, assess, and improve adherence to
secure-by-design practices across the software lifecycle.

Normative references (Secure by Design)

  1. 00 Principle Index
  2. 01 Security Governance
  3. 02 Risk-Driven Approach
  4. 03 Secure Product Development
  5. 04 Supply Chain Security
  6. 05 Usable Security Controls
  7. 06 Detect and Respond
  8. 07 Flexible Architecture
  9. 08 Minimize Attack Surface
  10. 09 Defense in Depth
  11. 10 Continuous Assurance
  12. 11 Secure Deprecation

Skill layout

  • SKILL.md — this file (skill entrypoint).
  • references/ — the Secure by Design normative documents.
    • 00-principle-index.md — index of all principle identifiers, categories, source mappings, and cross-references.
    • 01 through 11 — one document per synthesized principle area merging UK and AU guidance.

Third-Party Attribution

UK Government Secure by Design Principles

Australian ASD/ACSC Secure by Design Foundations

Categories