Chapter 1. Resilience in Software and Systems
The world stands on absurdities, and without them perhaps nothing at all would happen.
Fyodor Dostoevsky, The Brothers Karamazov
In our present reality, cybersecurity is more of an arcane art than science—an inscrutable, often excruciating, sequence of performative rituals to check boxes1 that affirm you’ve met the appropriate (and often arbitrary) regulatory or standards requirement. In terms of systems security, the ideal state is one of resilience—ensuring that systems can operate successfully now and in the future despite the dangers lurking in our digital world. To sustain resilience, we must understand how all the system’s machines and humans interact in pursuit of a common goal and how they respond to disruption.2 Knowing the intricacies of cybersecurity isn’t enough. We must understand the system’s resilience (or lack thereof) if we hope to protect it, which involves understanding the system’s dynamics, as we’ll explore in this chapter. This is why, throughout this book, we treat security as a subset of resilience.
This book is a practical guide for how to design, build, and operate systems that are more resilient to attack. We will prioritize progress over perfection. We will draw on lessons from other complex systems domains, like healthcare, aerospace, disaster recovery, ecology, urban infrastructure, and psychology; ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access