¨“Warm
fuzzies”: A belief that everything is “right enough” with their system
¨Absolution
from responsibility for anything bad that happens
–Followed “due diligence” process to prevent security
incidents
–Delegate “fault” for security incidents to developer or
evaluator