CWE
Home > CWE List > CWE-657 Individual Dictionary Definition (Draft 9)   View the CWE List

CWE-657 Individual Dictionary Definition (Draft 9)

Violation of Secure Design Principles
Weakness ID
Status: Draft

657 (Weakness Class)

Description

Summary

The product violates well-established principles for secure design.

Extended Description

This can introduce resultant weaknesses or make it easier for developers to introduce related weaknesses during implementation. Because code is centered around design, it can be resource-intensive to fix design problems.

References

Jerome H. Saltzer and Michael D. Schroeder. "The Protection of Information in Computer Systems". Proceedings of the IEEE 63. September, 1975. <http://web.mit.edu/Saltzer/www/publications/protection/>.

Sean Barnum and Michael Gegick. "Design Principles". 2005-09-19. <https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/principles/358.html>.

Relationships
NatureTypeIDName
ChildOfCategoryCategory17Code
ParentOfWeakness ClassWeakness ClassWeakness Class250Design Principle Violation: Failure to Use Least Privilege
ParentOfWeakness ClassWeakness ClassWeakness Class636Design Principle Violation: Not Failing Securely
ParentOfWeakness ClassWeakness ClassWeakness Class637Design Principle Violation: Not Using Economy of Mechanism
ParentOfWeakness ClassWeakness ClassWeakness Class638Design Principle Violation: Not Using Complete Mediation
ParentOfWeakness BaseWeakness BaseWeakness Base653Design Principle Violation: Insufficient Compartmentalization
ParentOfWeakness BaseWeakness BaseWeakness Base654Design Principle Violation: Reliance on a Single Factor in a Security Decision
ParentOfWeakness BaseWeakness BaseWeakness Base655Design Principle Violation: Failure to Satisfy Psychological Acceptability
ParentOfWeakness BaseWeakness BaseWeakness Base656Design Principle Violation: Reliance on Security through Obscurity
ParentOfWeakness ClassWeakness ClassWeakness Class671Design Principle Violation: Lack of Administrator Control over Security
Page Last Updated: April 22, 2008