This lesson covers the tenets of secure architecture and design; which are: • How much security is enough? • Defense in depth • Fail-safe • Economy of Mechanism (The K.I.S.S. Principle). • Completeness of Design • Least common mechanism • Open design • Consider the weakest link • Redundancy • Psychological acceptability • Separation of Duties (SOD) • Mandatory vacations • Job rotation • Least Privilege • Need to know • Dual Control

ISC2 Certified Secure Software Life-cycle Professional (CSSLP)