Threat-informed Business Security Architecture

The X and Y axis of Cybersecurity

There are always two sides to every story. In some cases, there are more, but most of the time, there are two.

When we talk about cybersecurity, those two sides are commonly known as defence and offence. Red team and blue team (no, I’m not forgetting about the purple team, but I’ll come back to that later).

Paradoxically, one side wouldn’t really exist without the other. If we didn’t have something of value to protect (defence), there wouldn’t be a threat (offence), and if we didn’t have a threat, we wouldn’t need protection.

In cybersecurity, we can’t succeed with just half of the story; we need to consider what must be protected and what is causing the need for protection - the threats.

A thorough understanding of both sides, defence and offence, is essential for cybersecurity to be effective in protecting the business/organisation as a whole.

So, how do we begin to understand both sides?

Like most complex things, there’s never a single right or wrong answer. The best answer is generally hidden somewhere in the middle. The grey zone. Or rather, the innovation zone as I like to call it.

The best answer I could come up with without being overly prescriptive with specific controls led me to SABSA.

Using the SABSA model, we have the following six frames:

1. What
2. Why
3. How
4. Who
5. Where
6. When

The goal is to work through these six frames, identifying the key information for each. Then, repeat the process using these six frames through each SABSA layer, ensuring your answers align with the business drivers and objectives. Depending on the scope/use case, not all frames and layers are required.

Now for the offence part. Here’s where we introduce the concept of threat-informed defence (TiD), and when it comes to that, there’s no better reference than MITRE ATT&CK.

Revisiting the six frames I covered earlier, but this time using a threat-informed approach. Focusing on the adversarial tactics, techniques, and procedures (TTPs) to better understand the most likely real-world threats.

Once all the inputs have been captured, this approach provides flexibility in that you can bring in any control family/framework that you like (NIST, ISO, CIS, etc.) to meet specific business and attack-driven security requirements and defence mechanisms.

Here is an example of what I ended up with.

The six frames of business security architecture - SABSA

Threat-informed Defence with Business Security Requirements

The key takeaway from all this is that a good security posture begins with the most valuable asset we're trying to protect: the business. However, defence is only half the battle.

SABSA provides a framework to bring defence and offence into the same picture in a structured way, enabling a threat-informed solution that aligns with the business goals.

Previous
Previous

Disrupting Nation-State Hackers

Next
Next

Zero Trust Architecture: NIST vs. MITRE ATTACK