01
Security Objectives
- Confidentiality protects information from unauthorized disclosure.
- Integrity protects information and computation from unauthorized modification.
- Availability keeps systems and resources accessible when required.
- Authenticity establishes confidence about identities or message origins.
- Accountability supports attribution and auditing.
02
Cryptography
Cryptography provides mathematical mechanisms for confidentiality, integrity, authentication, and digital signatures.
- Symmetric cryptography uses shared secrets.
- Public-key cryptography uses asymmetric key pairs.
- Hash functions map inputs to fixed-length digests.
- Digital signatures provide authenticity and integrity under defined assumptions.
03
Secure Design
- Least privilege.
- Defense in depth.
- Secure defaults.
- Input validation.
- Explicit authorization.
- Secrets management.
- Dependency management.
- Logging and incident response.