- Security has a bad reputation for getting in the way of real business
- This reputation has developed because of the way security professionals have practised
- We need an accurate definition of what we mean by ‘security’
- A technical definition of security may not be helpful
- Security can be defined only relative to the value and risk propositions of the business
- Risk is a combination of asset value, business impact, threat and vulnerability
- Risk management is a combination of risk assessment and ‘risk mitigation’