Tech

Security Engineering Analysis Framework Notes…

Good security engineering requires 4 things:

  • Policy: what you’re supposed to achieve
  • Mechanism–the ciphers, access controls, hardware tamper-resistance, and other machinery that you assemble in order to implement the policy.
  • Assurance–the amount of reliance you can place on each particular mechanism.
  • Incentive–the motive that the people guarding & maintaining the system have to do their job properly.