Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Kelly Shortridge, Aaron Rinehart

Rating No ratings yet

Cybersecurity is broken. Year after year, attackers remain unchallenged and undeterred, while engineering teams feel pressure to design, build, and operate "secure" systems. Failure can't be prevented, mental models of systems are incomplete, and our digital world constantly evolves. How can we verify that our systems behave the way we expect? What can we do to improve our systems' resilience? In this comprehensive guide, authors Kelly Shortridge and Aaron Rinehart help you navigate the challenges of sustaining resilience in complex software systems by using the principles and practices of security chaos engineering. By preparing for adverse events, you can ensure they don't disrupt your ability to innovate, move quickly, and achieve your engineering and business goals. Learn how to design a modern security program Make informed decisions at each phase of software delivery to nurture resilience and adaptive capacity Understand the complex systems dynamics upon which resilience outcomes depend Navigate technical and organizational trade-offs that distort decision making in systems Explore chaos experimentation to verify critical assumptions about software quality and security Learn how major enterprises leverage security chaos engineering

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Security Chaos Engineering: Sustaining Resilience in Software and Systems ## 【One-Line Pitch】 A practical guide for security and engineering leaders who want to move beyond broken prevention-focused security models and build systems that genuinely withstand attacks through continuous experimentation and resilience engineering. If you're tired of security theater and want evidence-based approaches that actually work in complex software environments, this book is for you. ## 【Book Arc】 - **Opening (~0%–9%)**: Establishes the core problem—cybersecurity is broken because it focuses on prevention and prediction rather than resilience. Introduces Security Chaos Engineering (SCE) as a framework that treats security as a subset of resilience, drawing lessons from healthcare, aerospace, and ecology. - **Early (~9%–25%)**: Explores complex systems dynamics, distinguishing between acute stressors (ransomware, exploits) and chronic stressors (tool sprawl, burnout, tech debt). Argues that chronic stressors quietly erode resilience, making systems vulnerable when acute events strike. Introduces the "safe-to-fail" philosophy. - **Early (~25%–34%)**: Makes the case for chaos experimentation as resilience stress testing. Emphasizes that prediction is impossible in complex systems and that experimentation generates tangible evidence for security decisions. Highlights software's unique privilege of testing in production. - **Middle (~34%–47%)**: Introduces the E&E (Evaluate and Experiment) Resilience Assessment Approach. Tier 1 focuses on documenting mental models through decision trees that map attacker actions and defense responses, enabling n-order thinking about adversarial behavior. - **Middle (~47%–53%)**: Transitions from assessment to experimentation. Tier 2 involves running chaos experiments to reveal constraints on adaptive capacity and uncover where systems drift toward failure thresholds. Emphasizes continuous learning and updating mental models based on evidence. ## 【Key Takeaways】 - **Prediction is a losing strategy** (Early): Complex systems defy accurate forecasting, so resources spent predicting attacks are wasted. Instead, invest in preparation and experimentation—"a building doesn't care if an earthquake was predicted; it will withstand the shaking, or it won't." - **Chronic stressors matter more than acute ones** (Early): Employee turnover, tool sprawl, tech debt, and burnout silently degrade resilience over time. When acute events like ransomware hit, systems are already weakened. Chaos experiments can reveal this drift. - **Security is a subset of resilience** (Early): The book reframes security as one aspect of broader system resilience, borrowing proven concepts from ecology, healthcare, and disaster recovery. This reframing enables more productive conversations and strategies. - **Chaos experiments are resilience stress tests** (Early): Simulating adverse conditions in production generates evidence about system behavior—especially unintended behavior. This evidence builds confidence and drives iterative improvement. - **Decision trees externalize mental models** (Middle): Mapping attacker actions and defense responses as decision trees forces second-order and n-order thinking. This helps teams anticipate adversary moves and identify security gaps before exploitation. - **Safe-to-fail beats fail-safe** (Middle): Design for decentralized, autonomous responses to local contexts rather than centralized control. Prioritize recovery, adaptability, and learning over preventing component failure. - **Incidents are learning opportunities, not blame events** (Middle): A learning mindset emboldens teams to improve resilience; a blame culture stifles curiosity and promotes punishment-avoidance behavior. Update decision trees with incident evidence to keep mental models honest. ## 【Reading Tips】 - **Skim the opening chapters** (~0%–9%) if you're already familiar with resilience engineering concepts; the core value is in the assessment framework and experimentation guidance that follows. - **Deep-read the decision tree chapter** (~34%–47%)—the S3 bucket example provides a concrete, walk-through template you can adapt for your own systems. - **Pay attention to the chronic vs. acute stressor lists** (~16%–19%)—these are practical diagnostic checklists for assessing your organization's resilience posture. - **The book is principle-focused, not tool-focused**—don't expect code examples or specific technology recommendations. Read for the trade-offs and decision frameworks. - **If you're an executive or manager**, focus on the resilience philosophy and the argument for experimentation; if you're a practitioner, focus on the E&E assessment methodology. ## 【Coverage Limits】 The excerpts cover the book's conceptual foundations, resilience theory, and the early stages of the E&E assessment framework (Tier 1). Detailed Tier 2 experimentation methods, organizational change strategies, and enterprise case studies are referenced but not fully covered in this guide. ##
Excerpt 1
39 Evaluation: Tier 1 Assessment 39 Mapping Flows to Critical Functionality 40 Document Assumptions About Safety Boundaries 41 Making Attacker Math Work for...
View in text
Excerpt 2
de: • Regular employee turnover • Tool sprawl and shelfware • Inability to update systems/software • Inflexible procedures • Upgrade-and-patch treadmill • Te...
View in text
Excerpt 3
stem and iteratively refine it, making chaos experiments an invaluable tool for each stage of the software delivery lifecycle (as we’ll explore throughout th...
View in text
Excerpt 4
tion in tier 2 can reveal the constraints on that capacity. 24 Christopher Nemeth et al., “Minding the Gaps: Creating Resilience in Health Care,” in Advances...
View in text
Excerpt 5
-as-a-service, the emerging (but not yet predominant) trend is for a system’s computer costs to represent a smaller portion of budget than the costs of the e...
View in text
Excerpt 6
rganizations likely have a system with scheduled processes— often in the form of scheduled jobs to inform business decisions, like calculating inventory or p...
View in text
Excerpt 7
than foreground. In an ideal world, security is invisible— the developer isn’t even aware of security things happening in the background. Their workflows don...
View in text
Excerpt 8
ective, manual deployments (and other parts of the delivery workflow) not only consume precious time and effort better spent elsewhere, but also tightly coup...
View in text
Tags
AI categories
securityresilience engineeringchaos engineering
ISBN: 1098113829
Publisher: O'Reilly Media
Publish Year: 2023
Language: English
Pages: 428
File Format: PDF
File Size: 14.2 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…