3 ms·
Of course you don't need to think of every possible way to compromise a system; just enough to reasonably protect against your threat model given the resources
by chousuke 6y ago
Of course you don't need to think of every possible way to compromise a system; just enough to reasonably protect against your threat model given the resources you have. If you have a complicated system that requires "hundreds of settings", then you just have to put more effort in making sure you don't miss anything.
I'm pretty sure most security breaches are caused by really basic configuration mistakes (or process failures). following a checklist can definitely be effective, but if you don't actually understand why you're configuring things as you are, you're likely to make mistakes elsewhere.