QOTD - Shostack on Security

Security is about outcomes, and our perceptions, beliefs and assurance about those outcomes. -- Adam Shostack, author of The New School of Information Security
Adam correctly points out that beyond the process, we need to measure the outcomes of our security efforts in order to validate that they are truly valuable.

Src: Security is about outcomes, not about process | Emergent Chaos

No comments: