1/15/07

Security

Security is a state of being free from danger or risks. It denotes the absence of risk which implies or denotes the absence of threats and or vulnerability. Security is not a meanigful concept without danger or threat, thus a system can not be considered secure or insecure if danger is not defined for the system.

This is an important concept, the fact that security is inherently tied to danger or threat! A system for which threat is defined but for which such threat is not a practical possibility is said to be practically absolutely secure. The converse is true.

Since threat is an indication of danger, a probability of danger, security can be defined as a measure of threat or expossure to danger.

Threat is not meaninful in the absence of an exploitable vulnerability, which is a weakness or potential expossure to danger.

We define security as that which imbues confidence in an enterprise from the perspective of the people involved in the enterprise; owners, stakeholders, investors, regulators, clients, partners, voters, candidates, etcetera.

No comments: