Chapter 6

Prevention is Ideal but Detection is a Must


We are at a very interesting time in security; the fundamental way we look at security has to change. In any area or sport but especially with security, offense is always easier than the defense. In order for the offense to be successful they only have to find one vulnerability or group of vulnerabilities. In order for the defense to win they have to find all of the vulnerabilities and fix them before the offense attacks and breaks in. While identifying and finding all of the vulnerabilities was never easy, in the past with proper planning and threat analysis organizations had a chance of keeping their organizations secure. In the 1990s while it was very difficult it was possible ...

