Chapter 15. Thinking about Security

Does Windows Vista change something fundamental about information security? This book has 14 chapters covering all things new in Windows Vista. It discusses all the things that make propeller hats spin. Yet these are just new features. Fundamentally, Windows Vista has not changed the information security landscape. The features change how we manage things, and to some extent, what we manage. But information security is far more than that. It is driven by external factors. One of the things that makes information security so fascinating, and so maddeningly frustrating, is that those of us on the good side are not entirely in control. The mark of good security is the ability to predict and preempt, not just respond. In security, regardless of whether it is information security, computer security, or airport security, those who can only respond are continuously dragged around by the nose by the bad guys. Those who can predict and preempt can change the playing field. To do that, we need to develop a discipline that is strategically sound, temporally stable, and flexible. Windows Vista may give us the flexibility, but without the remainder of the discipline, without the strategy, we will be unable to get ahead of the bad guys. That is why we still need to consider traditional defenses and adapt them tactically using our new tools. The previous 14 chapters were about the new tools. This one is about the strategy.

It Still Comes Down to Risk Management ...

Get WINDOWS VISTA™ SECURITY: Securing Vista Against Malicious Attacks now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.