Security Evaluation

Security Evaluation

Bruce Schneier
Beyond Fear
Copernicus books
2003
ISBN: 0387026207

Agenda

What is security?

Five steps process

3 final rules

  1. risk demystification
    • understand the threats
    • understand the risks
    • understand the effectiveness of the countermeasures
    • understand the trade-offs
    • understand the unintended consequences

3 final rules

  1. secrecy demystification
    • it is brittle
    • it causes additional security problems because it conceals abuse
    • it prevents from having the information needed to make sensible security trade-offs
  2. agenda demystification

Questions?