Module 2 Overview
January 18-24 · MLK Day is Monday, January 18 · Reading: 14 pages · Estimated total: 6.5 hours
In 1975 Jerome Saltzer and Michael Schroeder wrote down eight design principles for protecting information in computer systems. Fifty-two years later they are still the closest thing the field has to rules of thumb, and every serious breach you will read about this semester violates at least one of them.
This week you learn the eight, and then you learn why knowing them is not enough. The second half of the reading is about human factors, and it makes an uncomfortable point: most security controls that fail in practice fail because people route around them. When that happens, the usual response is to blame the people. CyBOK's position (and this course's) is that a control people cannot comply with is a defective control.
Learning Objectives
By the end of this week, the successful student will be able to:
- 1.3: Apply the Saltzer and Schroeder design principles to critique a familiar system.
- 1.4: Explain how human error and usability failures contribute to security incidents.
- 5.4: Apply fail-safe defaults and complete mediation when critiquing a system design.
Assignments and Tasks
Due by Sunday at 11:59 p.m. Mountain Time
- Read 2.01 Readings and Lecture Notes and work through the worked example (2 hrs 30 min)
- 2.02 Lab 1: Security Principles Audit (1 hr 25 min, 38 points)
No discussion this week. Lab 1 is the only graded item, and it is a writing assignment, so give it the full 85 minutes.
Time Estimate
| Activity | Time |
|---|---|
| Reading (14 pages plus the Saltzer & Schroeder excerpt) | 1 hr 50 min |
| The notes page and the worked example | 40 min |
| Lab 1 | 1 hr 25 min |
| Review and slack | 2 hrs 30 min |
| Total | ~6.5 hrs |
MLK Day falls on Monday, so the working week is short. Lab 1 is not due until Sunday.