The Open Worldwide Application Security Project, or OWASP, has introduced the Subtractive Security Top 10 Project, a security engineering initiative focused on eliminating attack paths rather than merely detecting or monitoring them. Traditional cyber defense often relies on adding security products, alerts, logging, endpoint tools, and access controls. The new OWASP project takes a different approach. It asks security teams a practical question: what can be removed to make an attack harder or impossible? The project is built on a simple principle: attackers can only use existing paths. If an organization removes unnecessary access, services, trust relationships, privileges, protocols, and network exposure, attackers have fewer...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!