Secure by Default
Kind: principle
Layer: Security Core
Aliases: Secure Defaults
Record: architecture:secure-by-default
Severity: mandatory
Scope: configuration, API, product
Canonical: Ontology
A design rule that every setting ships in its most restrictive safe state, and weakening one requires an explicit opt-in.
Listed in Architecture principles, after Zero Trust Architecture and before Attack Surface Reduction.