What is a model, what makes a good one, and why does it matter that many security standards are models?
A model is an incomplete representation of reality that makes certain aspects, mechanisms or relationships clear; a good model reduces complexity, explains, structures and orders. Many standards are models too, so they also show reality only incompletely.
The incompleteness is deliberate: a model leaves out what does not matter for its purpose, and that is exactly what makes it useful. A subway map is useless for walking distances and excellent for changing trains.
The consequence for cyber security architecture: when you apply a standard such as the ISO/OSI model or ISO 27001, remember that it covers some aspects of a real system well and ignores others. Treating a standard as a complete description of the system is how gaps go unnoticed.