JULY 2023ENTERPRISE SECURITY| | 19Companies are quickly adopting the Zero-Trust security model. Leaders are inundated with marketing hype around Zero-Trust, and it can be difficult to understand what is real, and what isn't. With hybrid and remote workforces becoming the new norm, companies have started embracing Zero-Trust at a faster rate. The White House even stated the importance of Zero-Trust in the "Executive Order on Improving the Nation's Cybersecurity", in May of 2021. A recent market research exercise conducted by The Demo Forum, found that there are now nearly 300 different vendors offering Zero-Trust security solutions. Why should your company consider adopting Zero-Trust and how can you properly communicate the benefits to your boards and stakeholders?Let us first demystify the term: Zero-Trust is not so much a product, as it is a mindset or paradigm that describes objectives and outcomes. Tools and products that claim to be Zero-Trust can help you evolve in ways to meet these objectives. But what's involved in developing a Zero-Trust strategy?One of the core principles of Zero-Trust is removing the implicit trust that we have within our IT environments. As we design our networks, we have evolved throughout the years as security professionals to think that "outside is bad", and "inside is safe". We protect our networks with firewalls to keep the bad guys out, and we usually assume that if something gets in that we don't want, we have a breach of security. The Zero-Trust mindset removes this way of thinking. Attributes like location and network have less importance on determining the level of trust of our assets and users (but can still be useful). With Zero-Trust, we treat every system with an equal risk profile, whether it is on or off our corporate network. A second main tenant of Zero-Trust is replacing that implicit trust with technology that dynamically monitors the trust level of users and assets and then adapts to it. One of the primary ways this is done is with identity. Zero-Trust solutions rely on continually determining the contextual identity of users and assets at any given time or location. A strong identity management solution is a must-have prerequisite for adopting Zero-Trust. The endresult is a model that "never trusts, but always verifies" our assets and users. This model is not only flexible enough for our post-COVID era hybrid workforces, but also positioned in a way that can prevent a minor compromise from becoming a large security breach. This all sounds fantastic, but how does this translate to actual technology? Below are some example data points on the technical aspects of Zero-Trust.ยท Remote workers no longer need to be directly connected to your corporate network to access corporate resources. This is usually achieved by using a service edge, sometimes called a secure access service edge (SASE). These can be cloud or perimeter based. These are fancy terms for proxies that present resources to clients if they are properly trusted. This subset of Zero-Trust is also known as Zero-Trust Network Access, or ZTNA.ZERO-TRUST: IS YOUR COMPANY READY?By Ben Schoenecker, Director of Information Security, Hendrick Automotive GroupBen SchoeneckerCXO INSIGHTS
<
Page 9 |
Page 11 >