LOGBOOK

HELP

1 / 14
Other keys: show • Space: good • 1-4: rate • 0: skip • 5: flag

Question

What is a model, what makes a good one, and why does it matter that many security standards are models?

Answer

A model is an incomplete representation of reality that makes certain aspects, mechanisms or relationships clear; a good model reduces complexity, explains, structures and orders. Many standards are models too, so they also show reality only incompletely.

The incompleteness is deliberate: a model leaves out what does not matter for its purpose, and that is exactly what makes it useful. A subway map is useless for walking distances and excellent for changing trains.

The consequence for cyber security architecture: when you apply a standard such as the ISO/OSI model or ISO 27001, remember that it covers some aspects of a real system well and ignores others. Treating a standard as a complete description of the system is how gaps go unnoticed.

or press any other key

Question

Which three general models and standards matter for applied cyber security architecture, and how do they differ in status?

Answer

The ISO/OSI reference model (a model that became a norm, 1983), ISO 27001 (a norm from the ISO 27000 family, 2005, revised 2013 and 2022) and the OWASP Top 10 (a quasi-standard, updated irregularly).

Status Since Covers
ISO/OSI reference model Model as a norm (ISO standard) 1983 Network communication in layers
ISO 27001 Formal norm from the 27000 family 2005, revised 2013, 2022 Requirements for an information security management system (ISMS)
OWASP Top 10 Quasi-standard (de facto, from a non-profit) Updated irregularly The most common security risks in web development

The difference in status matters in practice: an ISO norm can be audited and certified against; the OWASP Top 10 is a widely accepted reference, not a formal norm.

or press any other key