| Security Engineering |
Article Index for Security |
Website Links For Security |
Information AboutSecurity Engineering |
| CATEGORIES ABOUT SECURITY ENGINEERING | |
| security engineering | |
| cryptographysecurity engineering | |
| cryptography | |
| information technology | |
| security | |
| underpopulated categories | |
|
For this reason it involves aspects of Social Science , Psychology and Economics , as well as Physics , Chemistry and Mathematics . Some of the techniques used, such as Fault Tree Analysis , are derived from Safety Engineering . Other techniques such as Cryptography were previously restricted to military applications. One of the pioneers of security engineering as a formal field of study is Ross Anderson . QUALIFICATIONS Typical qualifications for a security engineer are:
However, multiple qualifications, or several qualified persons working in concert, may provide the more a compleat solution. {Link without Title} SECURITY STANCE Possible default positions on security matters: Default deny - "Everything not explicitly permitted is forbidden" -- Improves security at a cost in functionality. This is a good approach if you have lots of security threats. See Secure Computing for a discussion of Computer Security using this approach. Default permit - "Everything not explicitly forbidden is permitted" -- Allows greater functionality by sacrificing security. This is only a good approach in an environment where security threats are non-existent or negligible. See Computer Insecurity for an example of the failure of this approach in the real world. SUB-FIELDS
METHODOLOGIES Technological advances, principally in the field of Computer s, have now allowed the creation of far more complex systems, with new and complex security problems. Because modern systems cut across many areas of human endeavor, security engineers not only need consider the mathematical and physical properties of systems; they also need to consider attacks on the people who use and form parts of those systems using Social Engineering attacks. Secure systems have to resist not only technical attacks, but also Coercion , Fraud , and Deception by Confidence Trickster s. Computer - Patterns & Practices According to the ''Microsoft Developer Network'' the patterns & practices of Security Engineering consists of the following activities:
These activities are designed to help meet security objectives in the Software Life Cycle . Physical - Patterns & Practices
COMPANIES AND GOVERNMENTS EMPLOYING SECURITY ENGINEERS
CRITICISMS
| |||||||||||||||||||
|
|