| | December - JanuaryENTERPRISE SECURITY8IN MY OPINIONBy Raj Badhwar, SVP, Chief information security officer, Voya Financial, Inc. Cybersecurity Enabled by Zero TrustBIO:Raj Badhwar is SVP, Chief information security officer for Voya Financial, Inc. (NYSE: VOYA), which helps Americans plan, invest and protect their savings - to get ready to retire better.Raj has 25+ years of experience within the IT and Cybersecurity industry. He also held a top-secret clearance from the U.S. Department of Defense (DoD).Prior to joining Voya, Raj was the global head of information security for AIG, where he led global cyber security engineering and operations, aided by a strategy centered on the protection and preservation of IT systems, infrastructure and other computing assets. Prior to his role at AIG, he held senior Cyber Security and IT leadership roles at BAE Systems, Bank of America, Time Warner Cable and AOL Time Warner.Raj graduated from George Washington University (GWU) with a MS in information systems technology and also holds a BS in electrical and electronics engineering from Karnataka University.Raj is a director and secretary of the NTSC (National Technology Security Coalition) board. A member of the Rutgers University, and Ithaca College cybersecurity advisory boards, and an advisory adjunct to the SPARK Institute.He is a certified information systems security professional (CISSP), a certified ethical hacker (CEH), a FINRA licensed securities professional (Series 99), among many other technical certifications. He has also co-authored 14 security patents, and has written extensively in the areas of post quantum cryptography, zero trust networks, AI code of ethics for cybersecurity, cloud security patterns, and secure remote work paradigms.IntroductionCybersecurity professionals have all heard of the buzzword "Zero Trust," but few know what it means. The Zero Trust concept has come a long way in a decade, from the original 2010 Zero Trust model by John Kindervag of Forrester, the first implementation by Google (BeyondCorp) in 2013, followed by the Continuous Adaptive Risk and Trust Assessment (CARTA) model by Gartner in 2017, the Zero Trust extended (ZTX) Model by Forrester in 2018, to the Zero Trust Architecture (ZTA) by NIST. In spite of the various proposed models and architectures, and a proliferation of costly complex proprietary products from vendors who often fail to deliver, there is no single tool to achieve Zero Trust. Instead, "Zero Trust" calls for a fundamental shift in a firm's security paradigm across many levels. CISO's must make it their mission to provide clear and concise requirements for Zero Trust, along with practical guidance on implementations to secure their enterprise. I have highlighted the fundamental tenants of Zero trust below, along with commentary on how they may be implemented to provide better security.All assets inside and outside a perimeter firewall are not to be trustedWhether users, systems, or services are inside or outside the firewall, all must be treated as untrustworthy assets, which means they must be authenticated and authorized before use.This is enforced for external entities by a perimeter firewall, and for internal entities by higher-levelnetwork segmentation of (internal and external) DMZ, the Extranet, and the Intranet, as well as by also performing application segmentation.
<
Page 7 |
Page 9 >