FROM: http://lists.gnu.org/archive/html/l4-hurd/2005-11/msg00242.html

The user must be sure that his actions have predictable consequences, even in the presence of actively hostile influence. If there is a component in the system that the user can not control, the user must be able to contain its impact, either by simply ignoring it (shielding), or by imposing restrictions (confinement).

Security means that the user controls what can happen to his resources.

-- TomBachmann - 29 Apr 2006