Applying Security-by-Design Principles in Next-Generation Network Architectures: Implications for the United States and Global Cybersecurity Ecosystems
DOI:
https://doi.org/10.54536/ajet.v5i4.7688Keywords:
5G Networks, Cloud Security, Cybersecurity Policy, Edge Computing, ENISA Guidelines, Global Security Frameworks, ISO/IEC 27001, Network Security, NIST Framework, Secure Network Architecture, Security-By-Design, Zero Trust ArchitectureAbstract
The rapid growth of the digital ecosystem—driven by technologies such as 5G, cloud-native systems, edge computing, and the Internet of Things (IoT)—has introduced both significant opportunities and complex cybersecurity challenges. As modern networks become increasingly interconnected, traditional reactive security approaches are proving inadequate against evolving and sophisticated cyber threats. In this context, Security-by-Design (SbD) has emerged as a proactive approach that embeds security considerations into system architecture and throughout the development lifecycle.
This study examines the implementation of Security-by-Design principles in the United States and compares them with practices across Europe, the Asia-Pacific region, and Africa. The analysis draws on a combination of academic literature, policy documents, and established security frameworks, including NIST SP 800-207, CISA’s Zero Trust initiatives, ENISA guidelines, and ISO/IEC 27001 standards.
The findings indicate that the United States leads in aligning Zero Trust architecture with Security-by-Design principles, largely supported by federal mandates and national cybersecurity strategies. In contrast, other regions demonstrate strong governance frameworks, enhanced data protection regulations, and context-specific technological adaptations. The paper concludes by identifying ongoing global challenges, outlining future research directions, and recommending strategies to improve international collaboration in securing next-generation network infrastructures.
Downloads
References
Alcaraz, C., & Zeadally, S. (2015). Critical infrastructure protection: Requirements and challenges for the 21st century. International Journal of Critical Infrastructure Protection, 8, 53–66. https://doi.org/10.1016/j.ijcip.2014.12.002
Adu-Gyimah, S., Kufour Boansi, O., Asante, G., & Addo, P. C. (2025). Academic trust betrayed: Unravelling the factors behind lecturers’ vulnerability to social engineering attacks. American Journal of Education and Technology, 4(3), 53–61. https://doi.org/10.54536/ajet.v4i3.4773
Alharkan, I., & Aslam, N. (2021). Zero trust in cloud computing: A systematic review. IEEE Access, 9, 160027–160047. https://doi.org/10.1109/ACCESS.2021.3132025
Badr, Y., Chbeir, R., & Abraham, A. (2020). Security and resilience of next-generation cyber-physical systems. Future Generation Computer Systems, 108, 360–361. https://doi.org/10.1016/j.future.2020.03.044
Cisco. (2023). Zero-trust and secure-by-design networking: Architecture white paper. https://www.cisco.com
Cybersecurity and Infrastructure Security Agency. (2021). Zero trust maturity model. https://www.cisa.gov
European Union Agency for Cybersecurity. (2021). Access control and identity management guidelines. https://www.enisa.europa.eu
Fazil, A. W., Hakimi, M., Sajid, S., Quchi, M. M., & Khaliqyar, K. Q. (2023). Enhancing internet safety and cybersecurity awareness among secondary and high school students in Afghanistan: A case study of Badakhshan Province. American Journal of Education and Technology, 2(4), 50–61. https://doi.org/10.54536/ajet.v2i4.2248
Forrester Research. (2010). No more chewy centers: Introducing the Zero Trust model of information security (J. Kindervag).
Green, M., & Smith, M. (2016). Developers are not the enemy!: The need for usable security-by-design. IEEE Security & Privacy, 14(5), 40–46. https://doi.org/10.1109/MSP.2016.88
Hu, V. C., Ferraiolo, D., Kuhn, R., Schnitzer, A., Sandlin, K., Miller, R., & Scarfone, K. (2014). Guide to attribute-based access control (ABAC): Definitions and considerations (NIST SP 800-162). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-162
International Organization for Standardization. (2022). ISO/IEC 27001: Information security management systems—Requirements.
Kissel, R., Scholl, M., & Stine, K. (2012). Security considerations in the system development life cycle (NIST SP 800-64 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-64r2
Li, F., Hadjieleftheriou, M., Kollios, G., & Reyzin, L. (2005). Dynamic authenticated index structures for outsourced databases. The VLDB Journal, 14(4), 438–463. https://doi.org/10.1007/s00778-005-0168-2
National Institute of Standards and Technology. (2013). Security and privacy controls for federal information systems and organizations (NIST SP 800-53 Rev. 4). https://doi.org/10.6028/NIST.SP.800-53r4
National Institute of Standards and Technology. (2020). Zero trust architecture (NIST SP 800-207). https://doi.org/10.6028/NIST.SP.800-207
Roman, R., Zhou, J., & Lopez, J. (2013). On the features and challenges of security and privacy in distributed internet of things. Computer Networks, 57(10), 2266–2279. https://doi.org/10.1016/j.comnet.2012.12.018
Saltzer, J. H., & Schroeder, M. D. (1975). The protection of information in computer systems. Proceedings of the IEEE, 63(9), 1278–1308. https://doi.org/10.1109/PROC.1975.9939
Schneier, B. (2018). Click here to kill everybody: Security and survival in a hyper-connected world. W. W. Norton.
Srinivas, J., Das, A. K., & Kumar, N. (2019). Secure access control techniques in cloud computing: A comprehensive survey. Security and Communication Networks, 2019, 1–30. https://doi.org/10.1155/2019/8671864
Stallings, W. (2020). Network security essentials: Applications and standards (7th ed.). Pearson.
Sullivan, C., & Burger, E. (2017). Cybersecurity: A human-centric approach. American Journal of Law & Medicine, 43(2–3), 365–381. https://doi.org/10.1177/0098858817738222
UK National Cyber Security Centre. (2020). Principles for Zero Trust architecture. https://www.ncsc.gov.uk
U.S. Executive Office of the President. (2021). Executive Order 14028: Improving the nation’s cybersecurity. https://www.whitehouse.gov
Voigt, P., & von dem Bussche, A. (2017). The EU General Data Protection Regulation (GDPR): A practical guide. Springer. https://doi.org/10.1007/978-3-319-57959-7
Zetter, K. (2015). Countdown to zero day: Stuxnet and the launch of the world’s first digital weapon. Crown Publishing.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Akeem Ogundipe

This work is licensed under a Creative Commons Attribution 4.0 International License.




