Cybersecurity Threat Modelling and Zone-based Modelling
Put the Cart before the Horse
Quite often it is tempting for security professionals rushing out to buy firewalls, intrusion protection systems even before knowing what the cybersecurity threats and online attacks they are facing.
Threat Modelling
Threat modelling defines a narrow set of possible attacks to focus on; the attack samples are closer to specific industry the better. Such threat information can be collected from public threat databases and Verizon Data Breach Investigation Reports. A threat model can help to understand the "How" and assess the probability, the potential harm to an organization.
Zone-based Security Modelling
A zone is a grouping of assets (information, intellectual property, system, etc.) that share common security requirements. Based on the inputs of Threat Modelling the security professionals can work out necessary zone access matrix and then security controls and countermeasures to protect the assets.