For many decades, security engineering was a specialized topic, primarily considered within military organizations or by those working with them. Standards like TCSEC and ITSEC from the 1980s and 1990s, and later the Common Criteria, described the software-engineering activities needed to develop and validate security-critical systems. But for most non-military enterprises, security was a second …[more]