One of the principles it really emphasizes is that if you want to design a secure system, you need to *expect* that any individual component could fail, and plan accordingly.
One of the principles it really emphasizes is that if you want to design a secure system, you need to *expect* that any individual component could fail, and plan accordingly.