SLIDE 8 8
CS 1655 / Spring 2010 Alexandros Labrinidis, Univ. of Pittsburgh
15
Principles of Security Architecture
- 3. Decide how much security is just enough
degree of assurance required by your application is very
strongly related to:
size and nature of your unique risks Cost of counter-measures that you program
I.e., not make applications as secure as possible, BUT
make applications just secure enough
Of course, this level should be determined objectively, and not
because you ran out of time :-)
Ideally, there are standards, as in the financial sector Example:
require biometric identification for all amazon.com purchases
CS 1655 / Spring 2010 Alexandros Labrinidis, Univ. of Pittsburgh
16
Principles of Security Architecture
- 4. Employ standard engineering techniques
Good security requires good software design and design
techniques.
Main factors for security attacks:
Lack of any design Simple human weakness Poor coding practices
Good security architecture eliminates top two factors