@adamshostack@infosec.exchange
2026-09-24 21:50 UTC
In the first edition, I used the terms “diagram” and “model” nearly interchangeably. In the second, I get more specific about the differences. The dotted line in a diagram is showing a boundary, or the controls, or where there are different principals. And that’s what it is: A bunch of pixels which show the information. In a model, those properties can be specified and acted on. Or even derived: If each element in a model has an attribute about what account it runs with, then you can locate boundaries automatically. You may even be able to infer things about what enforces the boundary. (Unix kernels, AWS IAM, hope, etc.)
(2/9)
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-24 21:50
In the second edition, I use the term model in two distinct ways: the first is ‘any representation,’ while the second is a formalized construct with technical properties. (3/9)