| Admins | CIA | Do anything to increases availability. |
| ITSec/Infosec | CIA | Do anything to restrict people. |
About information security
- To work against an attacker, we need another mindset as we would need to protect agains a “simple” malfunction / bug in a system.
- We need to be able to reasoning in uncertainty, because we’ll never know all what is to know about a system — even our own.
Thoughts
“Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win.”
Defender and attacker mindsets
- Information security is about understanding the attackers mindset as well as understanding the technology.
- A small attack surface is easier to defend than a large one.