Posted in

What is the Zero Trust Model (ZTM)

The Zero Trust Model of information security simplifies how information security is conceptualized by assuming there are no longer trusted interfaces, applications, traffic, networks, or users. It takes the old model ” trust but verify ”and inverts it, because recent breaches have proven that when an organization trusts, it doesn’t verify [6].

This model requires that the following rules be followed [6]:

  • All resources must be accessed in a secure manner.
  • Access control must be on a need-to-know basis and strictly enforced.
  • Systems must verify and never trust.
  • All traffic must be inspected, logged, and reviewed.
  • Systems must be designed from the inside out instead of the outside in.

The zero-trust model has three key concepts:

  • Ensure all resources are accessed securely regardless of location.
  • Adopt a least privilege strategy and strictly enforce access control.
  • Inspect and log all traffic.

Outside-In to Inside-Out Attacks

According to a Forrester Research report, information security professionals should readjust some widely held views on how to combat cyber risks. Security professionals emphasize strengthening the network perimeter, the report states, but evolving threats ”such as increasing misuse of employee passwords and targeted attacks ”mean executives need to start buffering internal networks. In the zero-trust security model, companies should also analyze employee access and internal network traffic. One major recommendation of the Forrester report is for companies to grant minimal employee access privileges. It also emphasizes the importance of log analysis; another recommendation is for increased use of tools that inspect the actual content, or data packets, of internal traffic [1].

Teams within enterprises, with and without the support of information technology management, are embracing new technologies in the constant quest to improve business and personal effectiveness and efficiency. These technologies include virtualization; cloud computing; converged data, voice, and video networks; Web 2.0 applications; social networking; smartphones; and tablets. In addition, the percentage of remote and mobile workers in organizations continues to increase and reduce the value of physical perimeter controls [2].

The primary vector of attackers has shifted from outside-in to inside-out. Formerly, the primary attack vector was to directly penetrate the enterprise at the network level through open ports and to exploit operating system vulnerabilities. We call this attack methodology outside-in. In inside-out attacks, the user inside the protected network reaching out to an external website can be just as vulnerable as the user accessing the Internet from home [5].

Zero Trust Recommendations

  • Update network security with next-generation firewalls.
  • Use a sandbox control to detect unknown threats in files.
  • Establish protected enclaves to control user access to applications and resources.
  • Use a specialized anti-phishing email protection service.
  • Use threat intelligence to prioritize vulnerability remediation.
  • Analyze logs using advanced machine learning algorithms to detect compromised and malicious users.
  • Implement an incident management system to minimize the impact of individual incidents.
  • Deploy a cloud services manager to discover, analyze, and control shadow IT. (Shadow IT is hardware or software within an enterprise that is not supported by the organization’s central IT department.)
  • Monitor your partners’ security postures using a cloud-based service.
  • Deploy an enterprise key & certificate management system.
  • Deploy a backup, cloud-based DDoS mitigation service.
  • Deploy a non-signature-based endpoint malware detection control.

Just remember: the zero-trust model of information security means verify and never trust.

Ahmed Banafa, Author the Books:

Secure and Smart Internet of Things (IoT) Using Blockchain and AI

Blockchain Technology and Applications

Read more articles at: https://medium.com/@banafa

References

[1] https://www.securitymanagement.com/article/zero-trust-model-007894

[2] https://www.securityweek.com/steps-implementing-zero-trust-network

[3] https://spyders.ca/reduce-risk-by-adopting-a-zero-trust-modelapproach-to-security/

[4] https://www.cymbel.com/zero-trust-recommendations/

[5] https://csrc.nist.gov/cyberframework/rfi_comments/040813_forrester_research.pdf

[6] https://go.forrester.com/research/

Prof. Ahmed Banafa has extensive experience in research, operations and management, with focus on IoT, Blockchain, Cybersecurity and AI. He is a reviewer and a technical contributor for the publication of several technical books. He served as an instructor at well-known universities and colleges, including the Stanford University, University of California, Berkeley; California State University-East Bay; San Jose State University; and University of Massachusetts. He is the recipient of several awards, including Distinguished Tenured Staff Award, Instructor of the year for 4 years in a row, and Certificate of Honor from the City and County of San Francisco. He was named as No.1 tech voice to follow, technology fortune teller and influencer by LinkedIn in 2018 by LinkedIn, his researches featured in many reputable sites and magazines including Forbes, IEEE and MIT Technology Review, and Interviewed by ABC, CBS, NBC,BBC, NPR and Fox TV and Radio stations. He is a member of MIT Technology Review Global Panel.  He studied Electrical Engineering at Lehigh University, Cybersecurity at Harvard University and Digital Transformation at Massachusetts Institute of Technology (MIT). He is the author of the books: “Secure and Smart Internet of Things (IoT) using Blockchain and Artificial Intelligence (AI)” , and “Blockchain Technology and Applications” . Winner of Author & Artist Award 2019 of San Jose State University for "Secure and Smart IoT" Book.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.