Threat Modeling vs Information Classification
ID: fa0548c7-c81b-50fa-8a2d-0edb2ba87b67
STIX ID: report--fa0548c7-c81b-50fa-8a2d-0edb2ba87b67
Feed Name: SensePost Blog
The report argues that information-centric security is impractical in real-world environments due to shared data containers, attacker pivoting, and the criticality of system functionality beyond data sensitivity. It recommends prioritization based on threat-centric models, system/network trust segmentation, and attacker movement simulation, noting current limitations like immature DRM and data scarcity, with preliminary consideration of integrating VERIS metrics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
