How Many Controls do we Need to Reduce Risk?
When we’ve identified a risk to our design or user process – and that risk can pose a potential harm – how many controls do we need to add?
We discuss prevention vs. detection controls, ALARP, as low as possible, and some scenarios where we could (and maybe couldn’t) justify a risk as acceptable without adding additional controls.