I think that security is not a system, in the sense that Schneier is using. He calls it a process; that is okay, with the proviso that we're talking about a human process!
BTW. "Risk perception" is the keyword you're looking for. That there is a discrepancy between actual risk and risk perception is something that has been known for a long time, nothing new there.
Posted by Twan at January 14, 2007 12:37 PM