LOGBOOK

HELP

1 / 15
Other keys: show • Space: good • 1-4: rate • 0: skip • 5: flag

Question

Why do cyber security architecture models almost never appear alone in a real system?

Answer

Because real systems have grown over time and keep changing, so in practice you almost always find a combination of several models: combined deliberately to join their advantages or increase coverage, or combined badly because fragments were added over the years.

The environment of applied CSA has two features:

  • Grown structures: old legacy systems, systems in the own data centre, the most modern cloud services, all connected via the internet.
  • Continuous development: technologies and systems, attack methods, and CSA itself keep evolving.

So the CSA models are not single design patterns to apply in isolation. Combinations happen for good reasons (to combine advantages or raise the degree of coverage) and for bad ones: because IT systems grow over long periods and models or fragments of them are put together unfavourably, you will also meet unfavourable combinations.

or press any other key

Question

What is the basic idea of security-by-isolation, and why is complete isolation only a theory?

Answer

"My system cannot be reached, so it is secure": security by isolating the system from interaction. Complete isolation is theoretical because every cyber system has a task and needs a minimum of interaction.

It is the oldest security concept. The first computers had no cyber security of their own. They stood in suitably secured rooms, the threats assumed an attacker had to be physically present, and there was no networking and no remote access.

In reality you get extensive rather than complete isolation, because some interaction is always needed. Examples of minimal interaction:

  • a person operating a console directly at the system,
  • the control of an industrial plant connected to the cyber system.
or press any other key