云安全联盟-走向零信任架构:面向复杂和混合世界的指导性方法(英)-2021.10-30页_1mb
报告摘要
Summary of "Toward a Zero Trust Architecture"
Core Content
This document provides a comprehensive overview of the concept and implementation of Zero Trust Architecture (ZTA) in a complex and hybrid digital environment. It outlines the necessity of adopting ZTA due to the evolving nature of cybersecurity threats and the increasing reliance on cloud technologies. The paper emphasizes the importance of aligning ZTA with the broader goals of enterprise security, particularly under the U.S. government's regulatory and strategic frameworks.
Main Points
1. Why Zero Trust?
- Zero Trust (ZT) is a paradigm shift from traditional perimeter-based security to a model where trust is never assumed and always verified.
- The ZT model was introduced in 2003 by the Jericho Project, later implemented by Google in 2009 (Beyond Corp), and formalized by NIST in 2019 with SP 800-207.
- ZT principles include continuous verification, dynamic access control, and pervasive security controls that are applied closer to the data and functions they protect.
- ZT is essential for securing modern, hybrid, and multi-cloud environments, especially as organizations adopt microservices, IoT, and 5G.
2. Zero Trust Maturity Assessment
- Organizations must assess their current ZT maturity level to develop an effective ZTA roadmap.
- The CISA ZT-CMM framework outlines five pillars: Identity, Device, Networks, Application Workloads, and Data.
- A maturity assessment helps identify strengths and gaps, and informs the prioritization of investments and resources.
- The CISA ZT-CMM uses three levels: traditional, advanced, and optimal, to guide organizations in their ZT journey.
3. Developing a Zero Trust Roadmap
- The roadmap should be tailored to the organization's unique environment and business goals.
- It should incorporate industry best practices, such as NIST SP 800 series, CSA Cloud Controls Matrix (CCM), and STIGs.
- The roadmap should include a timeline for achieving targeted maturity levels and address the gaps identified in the assessment.
- Organizations should start with a single process, gradually expanding to a full ZTA implementation over one to three years.
Key Considerations for ZTA Adoption
4.1 Technology
- Modern IT environments require a shift from traditional perimeter-based security to ZT-centric technologies.
- Key technologies include Software-Defined Perimeter (SDP), Network Segmentation, Service Mesh, Edge Computing, Policy as Code, and Identity-Aware Proxy (IAP).
- Legacy systems are inadequate in addressing the complexity of modern attacks, and new technologies are essential for implementing ZT effectively.
4.2 Organizational Culture
- A "trust no one" mindset is critical for successful ZTA adoption.
- Cultural change is necessary to support the transition from traditional security practices to ZT.
- Organizations that embrace scalable cloud and hybrid models are better positioned to adopt ZT.
4.3 Policy
- Updating and aligning policies with ZT principles is essential.
- Policies must be dynamic, context-aware, and continuously managed.
- Organizations must identify and formalize new ZT-based policies, especially as they evolve in cloud environments.
4.4 Regulatory Environment
- The U.S. government mandates improved cybersecurity through Executive Order 14028 and the Federal Zero Trust Strategy.
- Compliance frameworks such as NIST's RMF and CSF provide guidance but are not specifically tailored to ZT.
- Regulatory initiatives help drive the development and adoption of ZTA, especially in federal agencies.
Zero Trust Solution Landscape
3.1 Software-Defined Perimeter (SDP)
- SDP is a key component of ZTA, providing secure access to applications by verifying identities and devices.
- SDP supports the "least privilege" principle by hiding applications and restricting access through a trusted broker.
- It is recognized as a "Network Layer Zero Trust" by the Cloud Security Alliance.
3.2 Network Segmentation
- Network segmentation (microsegmentation) is used to reduce the attack surface and prevent lateral movement.
- SDN enables dynamic and programmable segmentation, supporting the creation of granular security zones.
- Integration with DevSecOps pipelines and threat detection systems enhances the effectiveness of segmentation.
3.3 Other Solutions
- The paper also discusses the role of Service Mesh, Edge Computing, and Policy as Code in supporting ZTA.
- These technologies contribute to a more flexible, secure, and scalable approach to managing access and security in modern environments.
Recommendations
- Collaboration: Industry stakeholders should collaborate to develop and standardize ZTA best practices and maturity models.
- Customization: ZTA roadmaps must be customized to the specific needs and environment of each organization.
- Continuous Improvement: Organizations should use a capability maturity model (ZTA-CMM) to guide their journey and measure progress.
- Integration: ZTA solutions should integrate with existing technologies and processes to ensure a seamless transition.
- Education and Training: Security teams and business leaders must be educated on ZT principles and the cultural shift required for adoption.
Conclusion
The paper highlights the growing importance of Zero Trust Architecture in securing modern IT environments. It outlines the challenges of adoption, the key pillars of ZTA, and the recommended steps for developing a ZTA roadmap. The emphasis is on the need for industry collaboration, cultural change, and the integration of new technologies to achieve a mature and resilient ZTA.
试读结束,高清完整版pdf/doc/ppt,请点下载