LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

What is the Basic Cyber Security Model (BCS), and what does it say?

A deliberately minimal yardstick: looking at a cyber system, only (i) good actors, (ii) performing good actions, (iii) under desired states of the environment are permissible.

The Basic Cyber Security Model

* Only good actors, doing good actions, in a desired environment — three questions any design must answer. *

It is built up in three steps, each of which is a question you must answer about any real system:

  1. Fix the actors, interactions and services. An actor is the acting role — a person, or a service acting on behalf of something — and it triggers an interaction on a service. "Service" (S) here is any kind of cyber device whatsoever: a machine, a server, a piece of software, a web service, an IoT device, an application, a resource.
  2. Fix the system boundary of the cyber system under consideration: a technically and organisationally unambiguous delimitation of what is in and what is out.
  3. Distinguish good from bad — good actors from bad ones, good interactions from bad ones — and classify the environment into desired and undesired states.

The model's value is that it is independent of era and technology, so it can be used to compare approaches that look nothing alike. Every security approach in the history that follows can be graded against the same three clauses, and each one turns out to cover some clauses well and leave others open: perimeter security is largely about interactions and environment, AAA is almost entirely about actors, and so on.

Its practical use is as a review checklist. Put any design in front of it and ask: how do you know this actor is good? how do you know this action is good? how do you know the environment is in a desired state? Anything you cannot answer is where the design's real risk sits.

Tip: "only good actors, doing good things, in a good environment" sounds trivially obvious — which is the point. Almost no real system can demonstrate all three, and the gaps are the architecture's agenda.

Go deeper:

From Quiz: CSARCH / A Short History of Cyber Security Architecture | Updated: Sep 18, 2026