Bruce Schneier has a new essay on his blog, which should give anybody working in security a lot to think about.
In Nonsecurity Considerations in Security Decisions, Bruce talks, briefly, about what security *is*, then goes into trying to define *how* decisions about security are made. Something that jumped at me when I read it was:
At [...]