The outside zone represents untrusted networks, primarily the internet. Traffic from the outside zone has the lowest trust level. You assume it may contain attacks.
Default policies usually:
- Deny outside-to-inside traffic
- Deny outside-to-DMZ traffic (except specific permitted services)
- Permit established return traffic (responses to internal requests)
Your internet-facing firewall interface belongs to this zone. All traffic entering from outside is inspected against your security policies.