- Do No Harm
- Least Privilege
- Defense in Depth
- Security isn't an ROI calculation
- It is impossible to eliminate all risks
-
Rules of Risk Calculation and Mitigating Controls
-
Not all risks must be mitigated
-
Security is not just keeping the bad guys out
-
CIA Triad
- Confidentiality
- Integrity
- Availability
-
Preventation, Detection, Deterrents
-
Prevention fails
-
Security vs. Convenience