Skip to main content

Cybersecurity Threat Modelling and Zone-based Modelling

Put the Cart before the Horse

Quite often it is tempting for security professionals rushing out to buy firewalls, intrusion protection systems even before knowing what the cybersecurity threats and online attacks they are facing.

Threat Modelling

Threat modelling defines a narrow set of possible attacks to focus on; the attack samples are closer to specific industry the better. Such threat information can be collected from public threat databases and Verizon Data Breach Investigation Reports. A threat model can help to understand the "How" and assess the probability, the potential harm to an organization.

Zone-based security modeling

 

Zone-based Security Modelling

A zone is a grouping of assets (information, intellectual property, system, etc.) that share common security requirements. Based on the inputs of Threat Modelling the security professionals can work out necessary zone access matrix and then security controls and countermeasures to protect the assets.

Zone definition