Replying to
@adamshostack@infosec.exchange @pgl@infosec.exchange @jayjacobs@infosec.exchange I'm initially a fan of the explicit/implicit security policy violation, I think we'd need both: Someone could explicitly declare that they allow remote, unauthenticated access or control of a system, but everyone else may treat that as an implicit violation.