December 2020
Intermediate to advanced
361 pages
6h 26m
English
Risk assessment has already been discussed in detail in 12.12, so will not be discussed in much more depth here. However, it is worth looking at a condensed version of security guru Bruce Schneier’s five steps (or questions) that are intended as a mechanism for judging whether a certain security trade-off is worth making.97 The five questions are:
1.What assets are you trying to protect?
2.What are the risks to those assets?
3.How well does the security solution mitigate the risk?
4.What other risks does the security solution cause?
5.What trade-offs does the security solution require?
It is a straightforward approach that covers all the key points of making sensible security decisions. The first ...