To beat the bear

In May 2005 I wrote about the security analogy about the bear, two guys one of home stops to put on running shoes. Its “good enough security.” I dont have to outrun the bear, I just have to outrun you. I opined that that good enough security is only good enough for when your security exists only so you can check off a requirement with a regulatory agency. In reality, targeted attacks destroy “good enough” security. What if the bear doesn’t care about your slower friend, what about when its personal.
In the June 2006 issue of SC Magazine, the opening editorial makes use of this analogy and makes the point that good enough security doesn’t work against internal attacks either. They would argue that the main defenses are policies such as job rotation, separation of duties and rotation of duties.