User Objectives
¨ “Warm fuzzies”: A belief that everything is
“right enough” with their system
¨ Absolution from responsibility for anything
bad that happens
Followed “due diligence” process to prevent
security incidents
Delegate “fault” for security incidents to
developer or evaluator
600.436 High-
Assurance Systems
Fall 01/Introduction
7