Security · 1975 · Jerome H. Saltzer & Michael D. Schroeder

The Protection of Information in Computer Systems

Turn security into architectural reasoning through least privilege, fail-safe defaults, complete mediation, economy, open design, separation, and usable controls.

The central move

Turn security into architectural reasoning through least privilege, fail-safe defaults, complete mediation, economy, open design, separation, and usable controls.

Why it had to exist

Multi-user systems needed more than authentication features. Designers required principles that connected protected outcomes to mechanisms across the whole system.

Where it leads

Protection principles → access control and capability systems → zero trust, sandboxing, and secure defaults.

Study the guided reading in Bits →