THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Tuesday, May 17, 2022
A zero trust architecture is designed to combat lateral threat movement within a network by employing micro-segmentation and granular perimeter enforcement based on data, user, and location.
FREMONT, CA: A zero trust architecture (ZTA) is a security method that presupposes the untrustworthiness of all systems, networks, and people. It necessitates continual device, user, and application authentication.
A ZTA is built utilizing integrated technology solutions that adhere to zero trust principles.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
There are numerous approaches for a company to build a zero trust architecture. Here are several primary possibilities, each emphasizing a distinct aspect of the ZTA.
Enhanced Identity Governance for ZTA
This approach emphasizes the actor's identity in policy formulation. Enterprises specify the access criteria for each corporate resource based on the person or system's identification and assigned attributes. The primary criterion is to provide suitable access to resources for each user or system while excluding extraneous systems.
Micro-Segmented ZTA
This solution achieves zero trust by segmenting persons or groups of resources across many network segments and connecting them via secure gateways. Organizations can secure groups of resources by utilizing network equipment such as routers, switches, next-generation firewalls (NGFW), or software agents as a policy enforcement point (PEP).
ZTA with Network Perimeters Defined in Software
This method uses an overlay network, which is normally located at OSI layer 7 (the application layer), but may be lower in the network stack. This approach is referred to as Software Defined Perimeter (SDP) because it frequently uses Software Defined Networking (SDN) technology, which enables networks to be managed via flexible, virtualized appliances.
Building a Zero-Trust Architecture: Best Practices
Understand the Architecture
When constructing a ZTA, it is critical to map out the network's topology and become familiar with assets. Enterprises must understand their users, devices, and the services and data they access.
Particular care should be paid to components that make use of the network. Consider any network hostile—whether it is a private or public network that is not secured. Additionally, consider current services that were not designed for a ZTA and may be incapable of self-defense.
Establish a Robust Device Identity
Device identity is critical to a ZTA's success. It serves as the foundation for authentication, authorization, and other forms of security. It must be robust and distinctive.
The device's identifier must be—rather than being attached to the user, it is attached to the device. Identification of devices should be possible even if they are not connected to a network or are hidden behind a NAT device. The network verifies. A gadget should be incapable of claiming numerous identities or identities that are not theirs. Persistent and unaffected by the device's repurposing or replacement. Over time, this is verifiable. It should be easy to determine whether a device is still operational or whether it has been decommissioned—cross-network verifiability. When connected to many networks, even public ones, the same device should be able to establish its identity.
More in News