Skip to content

Side 67

Cybersecurity

A study of protecting systems under adversarial pressure. Cybersecurity begins by identifying assets and threats, reducing exploitable weakness, limiting access, detecting abnormal behavior and recovering from inevitable failure.

asset→threat→vulnerability→control→detect / recover
06security lenses
05control layers
05recovery questions
67Side

Security begins by defining what must be protected.

Controls make sense only relative to assets, plausible threats and the consequences of compromise.

01 · Asset

What has value?

Data, service, identity, process?

Security priorities depend on business and operational importance.

02 · Threat

What could cause harm?

Actor, accident, failure?

Threat modeling considers both adversarial and non-adversarial causes.

03 · Vulnerability

What weakness could be exploited?

Technical or procedural.

Weakness can exist in code, configuration, identity, process or people-system interfaces.

04 · Control

How is likelihood or impact reduced?

Prevent, detect, contain?

Controls should correspond to a defined risk rather than exist as ritual.

05 · Residual risk

What remains after controls?

Accept, transfer, reduce further?

No practical system reaches zero risk.

Identity is the control plane for authorization.

Security depends on knowing who or what is acting and limiting what that identity may do.

Authentication

Prove identity.

Credentials, keys or multiple factors establish who is requesting access.

Authorization

Decide permitted action.

Identity alone does not imply unlimited privilege.

Least privilege

Grant only needed access.

Smaller permission sets reduce blast radius if an account is compromised.

Separation

Split critical authority.

High-impact actions can require independent roles or approvals.

Lifecycle

Access changes with role and time.

Provisioning, review and revocation are as important as initial login.

Service identity

Machines need identities too.

Applications and workloads should authenticate rather than rely on network location alone.

Cryptography protects information through mathematical guarantees.

It can support confidentiality, integrity, authentication and nonrepudiation-like evidence, but only within a larger secure system.

Symmetric

One secret key.

Efficient encryption when communicating parties already share a secret.

Public key

Separate public and private keys.

Enables key exchange and digital signatures without pre-sharing one secret.

Hash

One-way fixed-size digest.

Hashes support integrity checking and other constructions.

Signature

Verify origin and integrity.

Digital signatures bind a message to control of a private key.

Key management

Protect the secrets behind the math.

Generation, storage, rotation and revocation often determine real-world security.

Secure systems reduce attack surface and contain compromise.

Defense in depth assumes any one control may fail.

LayerGoalExample controlFailure contained
EndpointProtect hostsPatching, hardening, application controlLocal compromise
NetworkLimit reachSegmentation, filteringLateral movement
ApplicationValidate behaviorInput validation, secure defaultsApplication misuse
DataProtect sensitive informationEncryption, access control, backupDisclosure or loss
Supply chainTrust dependencies deliberatelyProvenance, verification, updatesCompromised component

Prevention is incomplete without detection.

Monitoring looks for behavior inconsistent with expected system and user activity.

Logs

Record security-relevant events.

Useful logs preserve identity, time, action and outcome context.

Baseline

Know normal behavior.

Anomaly detection requires a reference for what typical activity looks like.

Alert

Surface suspicious patterns.

Alerts should be actionable enough to justify investigation.

Correlation

Connect weak signals.

Several low-confidence events together can reveal a stronger pattern.

Triage

Prioritize by consequence and confidence.

Analyst attention is finite and false positives have operational cost.

Hunt

Search proactively for hidden compromise.

Threat hunting tests hypotheses beyond automated alerts.

Security incidents are operational failures that require containment and learning.

Response aims to limit damage, restore trustworthy service and reduce recurrence.

Prepare

Define roles, communication paths, backups and recovery priorities before an incident.

Contain

Limit attacker or failure reach without destroying critical evidence unnecessarily.

Eradicate

Remove compromised credentials, malicious artifacts and root causes.

Recover

Restore clean systems and monitor closely for recurrence.

Learn

Convert incident evidence into stronger controls, architecture and operating practice.

Security EngineeringRoss Anderson · systems security
Computer SecurityStallings & Brown · security foundations
Cryptography EngineeringFerguson, Schneier & Kohno · practical cryptography
Incident response frameworkscontainment, recovery and learning