Compliance teams across the EU financial sector are increasingly being asked to justify not just what controls they have in place, but why those controls work.
Behind every access policy, segregation rule and monitoring system sits a formal information security model, and understanding these frameworks is becoming essential for compliance professionals navigating ISO 27001, DORA and NIS2.
RegTech firm Copla recently discussed information security models, and their types and how they work
Information security models translate abstract security goals into enforceable rules, typically mapped against the CIA triad of confidentiality, integrity and availability. Most financial institutions run several models in parallel rather than relying on a single approach.
Bell-LaPadula, developed originally for the US Department of Defense, governs confidentiality through “no read up” and “no write down” rules, underpinning the need-to-know principles found in ISO 27001 Annex A and DORA’s access management requirements. Its limitation is that it leaves data integrity unaddressed.
That gap is filled by the Biba model, which restricts users from reading lower-integrity data or writing to higher-integrity systems, a principle closely tied to change management requirements under ISO 27001 and DORA. Clark-Wilson extends integrity into business processes through well-formed transactions and separation of duties, effectively the theoretical basis for the four-eyes principle used in financial transaction authorisation.
The Brewer-Nash model, or Chinese Wall, addresses conflict of interest by dynamically blocking access to competitor data once a user has engaged with a rival firm’s information, a concept directly relevant to information barriers between divisions such as investment banking and asset management.
Role-based access control (RBAC) remains the most widely deployed model in practice, assigning permissions to roles rather than individuals, and is described as the operational backbone satisfying much of ISO 27001 and DORA’s access control expectations, provided review cycles produce genuine evidence rather than paperwork exercises.
Zero Trust, formalised under NIST SP 800-207, is framed as the most consequential shift in security architecture in the past decade. Built on verifying explicitly, enforcing least privilege and assuming breach has already occurred, it is presented as the single most efficient compliance investment available to EU financial institutions, satisfying multiple regulatory demands as a by-product of strong security design.
Layered on top is Defence in Depth, the principle that no single control failure should compromise an entire system, a concept reflected in ISO 27001’s Annex A control set and DORA’s operational resilience and third-party risk requirements.
For most EU financial institutions, the recommended combination is Zero Trust as the architecture, RBAC for access control, Defence in Depth for layering, and Clark-Wilson for transaction integrity, together addressing the bulk of ISO 27001, DORA and NIS2 obligations without duplicated control structures.
Read the full Copla post here.
Copyright © 2026 FinTech Global









