Website Security & Threat Management
Secure by default: recommendations from the CISA’s newest guide, and how Cloudflare follows these principles to keep you secure

Secure by default: recommendations from the CISA’s newest guide, and how Cloudflare follows these principles to keep you secure

4/20/2023 · Patrick R. Donahue, Ed Conolly

What this post added

This post details Cloudflare's adoption of 'Secure-by-Design' and 'Secure-by-Default' principles, aligning with CISA's recommendations. It highlights the rewrite of the WAF evaluation engine in Rust for memory safety and performance, and the automatic provisioning of SSL certificates as examples of these principles. The ML-computed WAF Attack Score is presented as a mechanism for protecting against zero-day attacks without manual configuration. Cloudflare Tunnel is also discussed as a secure-by-default solution for network connectivity.

Read the original post ↗