What has value?
Data, service, identity, process?
Security priorities depend on business and operational importance.
Side 67
A study of protecting systems under adversarial pressure. Cybersecurity begins by identifying assets and threats, reducing exploitable weakness, limiting access, detecting abnormal behavior and recovering from inevitable failure.
Controls make sense only relative to assets, plausible threats and the consequences of compromise.
Data, service, identity, process?
Security priorities depend on business and operational importance.
Actor, accident, failure?
Threat modeling considers both adversarial and non-adversarial causes.
Technical or procedural.
Weakness can exist in code, configuration, identity, process or people-system interfaces.
Prevent, detect, contain?
Controls should correspond to a defined risk rather than exist as ritual.
Accept, transfer, reduce further?
No practical system reaches zero risk.
Security depends on knowing who or what is acting and limiting what that identity may do.
Credentials, keys or multiple factors establish who is requesting access.
Identity alone does not imply unlimited privilege.
Smaller permission sets reduce blast radius if an account is compromised.
High-impact actions can require independent roles or approvals.
Provisioning, review and revocation are as important as initial login.
Applications and workloads should authenticate rather than rely on network location alone.
It can support confidentiality, integrity, authentication and nonrepudiation-like evidence, but only within a larger secure system.
Efficient encryption when communicating parties already share a secret.
Enables key exchange and digital signatures without pre-sharing one secret.
Hashes support integrity checking and other constructions.
Digital signatures bind a message to control of a private key.
Generation, storage, rotation and revocation often determine real-world security.
Defense in depth assumes any one control may fail.
| Layer | Goal | Example control | Failure contained |
|---|---|---|---|
| Endpoint | Protect hosts | Patching, hardening, application control | Local compromise |
| Network | Limit reach | Segmentation, filtering | Lateral movement |
| Application | Validate behavior | Input validation, secure defaults | Application misuse |
| Data | Protect sensitive information | Encryption, access control, backup | Disclosure or loss |
| Supply chain | Trust dependencies deliberately | Provenance, verification, updates | Compromised component |
Monitoring looks for behavior inconsistent with expected system and user activity.
Useful logs preserve identity, time, action and outcome context.
Anomaly detection requires a reference for what typical activity looks like.
Alerts should be actionable enough to justify investigation.
Several low-confidence events together can reveal a stronger pattern.
Analyst attention is finite and false positives have operational cost.
Threat hunting tests hypotheses beyond automated alerts.
Response aims to limit damage, restore trustworthy service and reduce recurrence.
Define roles, communication paths, backups and recovery priorities before an incident.
Limit attacker or failure reach without destroying critical evidence unnecessarily.
Remove compromised credentials, malicious artifacts and root causes.
Restore clean systems and monitor closely for recurrence.
Convert incident evidence into stronger controls, architecture and operating practice.