In parts 1 and 2, we talked about various forms of security testing and evaluation by telling a story about a concerned parent purchasing (and evaluating) a car for the newly licensed teenaged daughter. Now, let's talk about the mechanic for a bit.
You, fortunately, have
had a car before, and have had the opportunity to work with this
mechanic before. He set your expectations, you’ve seen what he’s done
before, and you generally have good reasons to trust
him because you know what you want is what he is going to give you.
You’ve already got a mutually established language. His services are
clearly defined. You know what to expect.
What if you’ve never
had a car before, and you don’t know any mechanics?