The Security Stack: A Model for Understanding the Cybersecurity We Need

This paper proposes a four-layer model called the Security Stack as a means to visualize the ocmplexity of cybersecurity problems and see through to comprehensive, effective solutions. The authors use the term Security Stack as analogous to other well accepted stacks, (e.g., the OSI model) where layers deliver services and exchange information to achieve a higher level serve. The notion of a Security Stack serves the proposition that security must be an integrated set of services. The paper defines each layer, offers examples of enabling technologies, related standards and types of professional security services that implement the enabling technologies. It also notes where adequate enabling technologies or standards need to be developed, or where policies need to be set and implemented to allow information to be exhanged between layers fast enough to keep up with the speed of emerging threats.

