Skip to content

Latest commit

 

History

History
30 lines (18 loc) · 513 Bytes

Principles.md

File metadata and controls

30 lines (18 loc) · 513 Bytes

Security Principles

Work In Progress...

  1. Do No Harm
  2. Least Privilege
  3. Defense in Depth
  4. Security isn't an ROI calculation
  5. It is impossible to eliminate all risks

Additional Candidate Principles...

  • Rules of Risk Calculation and Mitigating Controls

  • Not all risks must be mitigated

  • Security is not just keeping the bad guys out

  • CIA Triad

    • Confidentiality
    • Integrity
    • Availability
  • Preventation, Detection, Deterrents

  • Prevention fails

  • Security vs. Convenience