Security through Obscurity: A criticized practice that relies on keeping security mechanisms secret as the main method of protection. It is generally considered inadequate because once the obscurity is bypassed, there are no other defenses. Effective security should not depend solely on the secrecy of its implementation but rather on robust, tested, and transparent methods. Security through obscurity is best paired with a ‘defense in depth’ approach.
Categories: CC D5: Security Operations | CCSP D6: Legal - Risk and Compliance | CISM D3: Information Security Program | CISSP D1: Security and Risk Management | Security+ D1: General Security Concepts | SSCP D1: Security Concepts and Practices
« Back to Glossary Index