News

Zero Trust – Avoiding the Paranoid Posture of “Trust No One”

February 13, 2024

The approach for protecting our digital assets from cybercrime, fraud, and abuse has been coined by the cybersecurity industry as “Zero Trust” and even defined as an architecture approach by NIST 800-207. At first glance, it appears that the pendulum on managing digital threats seems to have turned towards an almost paranoid response: “Trust No One”.  However, no business model can survive if it restricts access to a point with which it is considered hard to do business.  Successful companies build trust with consumers, employees and partners early and reinforce it as often as possible, so claiming “Zero Trust” may seem paranoid or counterintuitive for growing any business.

So, let’s demystify the paranoia.  The Zero Trust Architecture is a set of guiding principles within an architectural framework that can be incorporated into your Cybersecurity and Compliance Programs.  It is not a project that has an end date but a philosophy that involves continuous authentication and authorization for securing access during a connected session with all actors (Person, Service Account, Bot, etc.).  This philosophy cannot be solved using a single product but requires an orchestration of products, workflows, policies, standards, and procedures across an architecture to achieve a higher level of security and mature an organization's risk posture. 

NIST 800-207 Basic Guiding Principles:

  • prevent unauthorized access to data and services
  • access control enforcement as granular as possible

There is nothing mysterious in these principles, as most security professionals would agree they are best practices.  However, granular enforcement is where the real challenges begin to stress the existing infrastructures and access control systems.  Many of the current systems today leverage Groups or Roles and static access entitlements through either direct (account has the permission assigned) or indirect access (account’s permission is granted via a group or role membership entitlement).  Static permissions granted to accounts is where risk is not fully minimized and truly granularly enforced.

Network Trust Zones, Role Based Access Control (RBAC) and Attribute Based Access Control (ABAC) systems are the current goto staples to establish granular access.  However, these systems typically grant permissions as static entitlements which means while they may appear to be least privileged from a business role or policy perspective, they are not least privileged from an overall security posture. The 7 tenets of the Zero Trust Architecture adds secured communication and real-time or dynamic policy enforcement components across all resources to granularly control least privilege at the session control and transaction level given the current access context, vs the account or user level access permissions always enabled regardless of context. 

Tenets of Zero Trust

  1. All data sources and computing services are considered resources.
  2. All communication is secured regardless of network location.
  3. Access to individual enterprise resources is granted on a per-session basis.
  4. Access to resources is determined by dynamic policy—including the observable state of client identity, application/service, and the requesting asset—and may include other behavioral and environmental attributes. 
  5. The enterprise monitors and measures the integrity and security posture of all owned and associated assets.
  6. All resource authentication and authorization are dynamic and strictly enforced before access is allowed.
  7. The enterprise collects as much information as possible about the current state of assets, network infrastructure and communications and uses it to improve its security posture.

A Zero Trust View of a Network

  1. The entire enterprise private network is not considered an implicit trust zone.
  2. Devices on the network may not be owned or configurable by the enterprise.
  3. No resource is inherently trusted.
  4. Not all enterprise resources are on enterprise-owned infrastructure.
  5. Remote enterprise subjects and assets cannot fully trust their local network connection.
  6. Assets and workflows moving between enterprise and non-enterprise infrastructure should have a consistent security policy and posture.

The New Zero Trust philosophy brings new challenges

“Tesler’s Law” or “Law of conservation of complexity” will take some time to play out as businesses wrestle with how to break down existing access control methods to support a “Zero Trust” Network strategy.  Some may consider buying and implementing a single centralized policy decision point and scaling out the policy enforcement points.  While others will see the benefits of having multiple specialized policy engines and dynamic decision points scaled to their unique purpose (Storage, Communications, Data Access Governance, Transactions, Application Resources, etc.).

I like to think of this as developing a Civilized Digital Society and Digital Nation building.  For example, do you need a State law enforcement model (e.g. Policy force with a National Guard directed by a strong Governor to back them up), or do you need a Federal Defense model (e.g. Army, Airforce, Navy,  Marines and Space Force with a Pentagon and a Congress to establish policies) to manage, control and enforce the laws (policies)?  These decisions will need to be driven by the overall business drivers and the Governance, Risk and Compliance (GRC) strategy of the business across all system resources. 

NIST 800-207 suggests best practices such as  “Enhanced identity governance-based” or “identity-driven” approaches be leveraged as a centric “Policy Decision Point” service.   With this approach, “Policy Enforcement Points” or PEPs can leverage the Identity Governance policies consistently and enforce access dynamically (e.g. real-time ) vs. always granted enforcement methods.

Next Steps - Avoid the Paranoia

  1. Begin the process of determining if Zero Trust fits into your Cybersecurity strategy and how it aligns with the Identify Governance Program by taking a “Systems thinking” approach to evaluating the benefits vs costs.
  2. Establish a method to ensure the organization has an awareness and training program that incorporates the overall concepts of Zero Trust.
  3. Evaluate and prioritize where to start by incorporating the Zero Trust philosophy into the Architecture Roadmap. 
  4. Determine quick wins and areas that can be improved with existing identity governance and policy enforcement capabilities.
  5. Begin to evaluate the market place for Zero Trust tools that complement existing capabilities or expand services that can begin to mature the protection of the critical and high risk resources.
  6. Consider performing Product Evaluation Workshops, Demonstrations and Proof of Concepts to ensure  investments will align with the strategy and achieve expected outcomes.
  7. Evaluate the overall user experience and complexity zero trust carries with it in conjunction with the expected and measured security risks being enforced and matured to ensure an optimum outcome can be achieved.

Basically, Zero Trust and NIST 800-207 should be approached from a principled, strategic, systems thinking methodology to avoid the appearance of being paranoid and too restrictive.  Like water, employees, customers and partners in the marketplace will flow to those businesses who have made the journey more secure, seamless, frictionless, and ultimately more enjoyable.

Want to know more about the journey to ZTA? Talk to our experts anytime here.

More News

Subscribe To Our Newsletter

Please send me the following content from Idenhaus:*
Select as many boxes as you'd like!
Idenhaus needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.