Yet Another Paradigm!
Matthew Pemble · Network Security · 2001
The consensus view in the profession is that security is a people problem, not a technical one. Lots of people have articulated this, particularly Bruce Schneier in his recent testimony to the US Congress. I, myself, state this “fact” regularly in presentations and lectures as my “Second Law of Computer Security” (subordinate only to “Security must be appropriate for the particular business requirement”). Recent experience in conducting a security audit in a major multinational utilities company, has lead me to reconsider whether this is the key message to get across to systems designers, purchasers and operators.