In Threat-Driven Software Development, we focus heavily on the nuances of Operational Security and how to secure online services from modern threat actors. There are many books on Application Security, but not on this important operational aspect. How are they different? I think this quote sums it up best:
Application Security is an investment. Operational Security is a commitment.
Here is the full exerpt:
Understanding operational security
One phrase really helps underscore the difference between application security and operational security:



