Security · 1975 · Jerome H. Saltzer & Michael D. Schroeder
The Protection of Information in Computer Systems
Turn security into architectural reasoning through least privilege, fail-safe defaults, complete mediation, economy, open design, separation, and usable controls.
The central move
Turn security into architectural reasoning through least privilege, fail-safe defaults, complete mediation, economy, open design, separation, and usable controls.
Why it had to exist
Multi-user systems needed more than authentication features. Designers required principles that connected protected outcomes to mechanisms across the whole system.
Where it leads
Protection principles → access control and capability systems → zero trust, sandboxing, and secure defaults.