Question
What is a model, what makes a good one, and why does it matter that many security standards are models?
Answer
A model is an incomplete representation of reality that makes certain aspects, mechanisms or relationships clear; a good model reduces complexity, explains, structures and orders. Many standards are models too, so they also show reality only incompletely.
The incompleteness is deliberate: a model leaves out what does not matter for its purpose, and that is exactly what makes it useful. A subway map is useless for walking distances and excellent for changing trains.
The consequence for cyber security architecture: when you apply a standard such as the ISO/OSI model or ISO 27001, remember that it covers some aspects of a real system well and ignores others. Treating a standard as a complete description of the system is how gaps go unnoticed.
Note saved — thanks!
Question
Which three general models and standards matter for applied cyber security architecture, and how do they differ in status?
Answer
The ISO/OSI reference model (a model that became a norm, 1983), ISO 27001 (a norm from the ISO 27000 family, 2005, revised 2013 and 2022) and the OWASP Top 10 (a quasi-standard, updated irregularly).
| Status | Since | Covers | |
|---|---|---|---|
| ISO/OSI reference model | Model as a norm (ISO standard) | 1983 | Network communication in layers |
| ISO 27001 | Formal norm from the 27000 family | 2005, revised 2013, 2022 | Requirements for an information security management system (ISMS) |
| OWASP Top 10 | Quasi-standard (de facto, from a non-profit) | Updated irregularly | The most common security risks in web development |
The difference in status matters in practice: an ISO norm can be audited and certified against; the OWASP Top 10 is a widely accepted reference, not a formal norm.
Note saved — thanks!