TIL about McCumber cube. So everyone knows about the CIA triad. All of the info sec books talk about the CIA triad extensively. Now imagine making a 3D rubiks cube version off of the CIA triad. That's the McCumber cube.
It has 3 main dimensions which are further divided into 3 goals.
Dimension 1 - InfoSec properties - Confidentiality, Integrity, Availability
Dimension 2 - Data and its states - At rest, in processing, in transit
Dimension 3 - Security Measures - Policy/Procedure , Technology, Training/Education.
Ohkay but how do we use it ?
It helps to evaluate if the info sec program you are implementing is tackling all the different combinations of scenarios.
Example: Do you have a POLICY regarding data CONFIDENTIALITY for DATA AT REST? Here we are evaluating based on one property from each of the 3 dimensions.
Is there a visual representation for this:
https://ioc.pub/url/snake-goat-panda
More reading:
https://ioc.pub/pasta/sheep-pony