LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

What does security-on-the-system do, and why is the system simultaneously the best and the worst place to put security?

It reduces the attack surface directly on the target — patching, minimalism, hardening, application-level controls. The system is the most powerful control point because it has everything needed to judge a request, and the biggest potential weakness for exactly the same reason.

The measures are the familiar operational core:

  • Eliminate known vulnerabilities and keep all parts up to date.
  • Reduce the system to what is necessary — the minimal principle: every service, package, account and open port that does not need to exist is attack surface that costs nothing to remove.
  • Harden the system, with some smart security tools on it.
  • Implement application-level controls on the system itself.

The double-edged property is the real lesson. In the system, all the possibilities for processing a request are present: it knows the user, the session, the data, the business context and the actual intent of the call. No firewall or proxy in front of it has that information. That makes it the most powerful control point — and simultaneously the largest potential weakness, because everything an attacker needs is likewise present there, and a single flaw in that one place bypasses all the control it could have exercised.

Two practical constraints follow:

  1. Quality depends entirely on implementation. "Security on the system" is only as good as the hardening and the code — it is not a property you can buy and place in front of something.
  2. Not every system can carry the extra load. Security controls cost CPU, memory and latency, and plenty of systems — OT above all — have no headroom for them, which is precisely why OT keeps appearing as a hard case.

Go deeper:

From Quiz: CSARCH / A Short History of Cyber Security Architecture | Updated: Sep 18, 2026