Overview
Syllabus
Intro
Security Design & High-Risk Users
The ability to define and determine what a technical system will and will not do is necessary but not sufficient to determine whether it is secure. Defining security for a system means understanding what your humans want.
Security design is the process of understanding user culture, goals, and workflows, organizational Technical capabilities, and adversary capabilities and dispositions and synthesizing a satisficing solution.
Outcomes are messy
Worse Better
Mapping the Security Task
Taught by
Hack In The Box Security Conference