Mistaking other things for security
Security is a complex and multi-faceted domain. This complexity can be so profound in many cases that a strong temptation arises to simplify it to something more manageable. In this section, we will see two examples of how this can occur and what the negative consequences can be.
Compliant Is Secure
Example
Alexandra works as an architect for LifeCo, a major provider of medical devices for the continuous measurement of vital statistics. They sell devices across a number of global markets and as a consequence are subjected to a number of different regulatory regimes. It is fair to say that a big part of LifeCo’s culture is focused on meeting these regulatory requirements and maintaining compliance.
When it comes to IT security, LifeCo has also adopted a compliance-centric approach, combining...