Security Engineering Analysis Framework Notes…
Good security engineering requires 4 things:
- Policy: what you’re supposed to achieve
- Mechanism–the ciphers, access controls, hardware tamper-resistance, and other machinery that you assemble in order to implement the policy.
- Assurance–the amount of reliance you can place on each particular mechanism.
- Incentive–the motive that the people guarding & maintaining the system have to do their job properly.