{"id":11659,"date":"2022-10-27T14:02:03","date_gmt":"2022-10-27T08:02:03","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=11659"},"modified":"2022-10-27T14:02:03","modified_gmt":"2022-10-27T08:02:03","slug":"7-key-considerations-for-adopting-zero-trust","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/7-key-considerations-for-adopting-zero-trust\/","title":{"rendered":"7 key considerations for adopting zero trust"},"content":{"rendered":"<p>When we look at Zero Trust, it helps to take a step back. The internet is flooded with articles, hot takes, and it\u2019s all too easy to get caught up in the hype. We run the risk of going too fast and missing important fundamentals. There\u2019s an airplane analogy &#8212; in turbulence, a rookie pilot might be tempted to speed up and get through the storm quickly. That, however, will lead to instability and further risk of peril. The more experienced pilot cuts all that is unnecessary, slows down, and stabilizes the aircraft.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11662\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2022\/10\/gaw.jpg\" alt=\"\" width=\"640\" height=\"464\" \/><\/p>\n<p>That\u2019s what we need to do with Zero Trust: look before we leap, prioritize alignment and consistency, and avoid the hype. We\u2019re developing the security architecture that will underpin our organizations as they plant their flag in the digital revolution. As threats increase and margins of error decrease, doing it right the first time will make a big competitive difference in the future.<\/p>\n<p><strong><b>Zero Trust is confusing<\/b><\/strong><\/p>\n<p>Zero Trust can often engender confusion. We struggle to find consensus on what exactly Zero Trust is, whose definition to use, what\u00a0exactly\u00a0it entails, or who\u2019s doing it right. It\u2019s a bit of a &#8220;throw spaghetti at the wall&#8221; deal and we\u2019re hoping things stick.<\/p>\n<p>As security practitioners, we heed the temptation to rush towards the &#8220;new\u00a0new thing&#8221; and can forego the necessary internal strategy discussions first. You don\u2019t know how to get where you\u2019re going without a map, so start there. Next there\u2019s the sprawl. No perimeter means boundless options for securing an even more overwhelming number of vectors. And we\u2019re supposed to secure all that to the Nth degree?<\/p>\n<p>If this is possible to\u00a0any\u00a0degree, it will require a paradigm shift. And that precipitates a return to basics.<\/p>\n<p><strong><b>Prepare<\/b><\/strong><\/p>\n<p>To push through an organization-wide initiative that will affect the day-to-day work of all departments in IT, security, and operations, you need to have all the right people on board. That\u2019s why alignment is not an option, it\u2019s a bare minimum. Create a core team of key players that are &#8220;restless for better&#8221;, taken from the ranks of Ops, Red Teams, Blue Teams, and IT infrastructure, among others.<\/p>\n<p>Next, establish a solid understanding of Zero Trust within that group. It\u2019s fine to take a while on this step &#8212; this will lay the groundwork for all the others, so dig into the data. Learn about Zero Trust architecture, the recommendations and frameworks, and establish a plan of how you\u2019re going to apply the data to your organization. Here\u2019s a great set of foundational resources I\u2019d recommend you and your team start with:<\/p>\n<ul>\n<li><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-207\/final\"><u>NIST SP 800-207 Zero Trust Architecture<\/u><\/a><\/li>\n<li><a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/Library\/(U)ZT_RA_v1.1(U)_Mar21.pdf\"><u>Department of Defense (DoD) Zero Trust Reference Architecture<\/u><\/a><\/li>\n<li><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/white-paper\/2021\/08\/04\/planning-for-zero-trust-architecture-starting-guide-for-admins\/draft\"><u>Planning for a Zero Trust Architecture: A Starting Guide for Administrators (NIST)<\/u><\/a><\/li>\n<li><a href=\"https:\/\/www.nist.gov\/publications\/risk-management-framework-information-systems-and-organizations-system-life-cycle\"><u>NIST Risk Management Framework for Information Systems and Organizations<\/u><\/a><\/li>\n<li><a href=\"https:\/\/media.defense.gov\/2022\/Jun\/15\/2003018261\/-1\/-1\/0\/CTR_NSA_NETWORK_INFRASTRUCTURE_SECURITY_GUIDE_20220615.PDF\"><u>NSA Network Infrastructure Security Guidance<\/u><\/a><\/li>\n<li><a href=\"https:\/\/www.cisa.gov\/zero-trust-maturity-model\"><u>CISA Zero Trust Maturity Model<\/u><\/a><\/li>\n<\/ul>\n<p>Once you\u2019ve familiarized yourself with the literature, it\u2019s time to start. Take a methodical approach to Zero Trust adoption, and you\u2019ll find your changes &#8220;stick&#8221; &#8212; not only in the architecture, but with those who are going to implement, use and maintain it.<\/p>\n<p><strong><b>Categorize<\/b><\/strong><\/p>\n<p>What would happen if Asset X was compromised? What about from there? That will guide your priorities. And remember, when categorizing your assets and their respective values, simple is best.<\/p>\n<p><strong><b>Select<\/b><\/strong><\/p>\n<p>It\u2019s the survival of the most important. Once you\u2019ve categorized it into &#8220;my business couldn\u2019t live without\u00a0this&#8221; and on downward from there, you establish your protection surface. Draw a line around those key assets and secure them first. Pick your top ten to work on, then start on your top three. Yes &#8212;\u00a0only\u00a0the top three.<\/p>\n<p><strong><b>Implement<\/b><\/strong><\/p>\n<p>This is the ops stage. Look around now and determine what you have in terms of resources, and what you still need. Find a handful of great partners and services then build out your strategy from there. Lean on your core team. Remember when you pulled them from all different parts of IT? This is where they really shine, taking ownership over their own individual specialties and making sure the Zero Trust architecture there is implemented with accuracy, completeness, and compliance. Don\u2019t reinvent the wheel between departments; try to stick with consistent policies across the board.<\/p>\n<p><strong><b>Assess<\/b><\/strong><\/p>\n<p>Now it\u2019s time for the stress test. How well does your\u00a0<a href=\"https:\/\/cyberprotection-magazine.com\/the-role-of-a-zero-trust-network-in-your-organisations-digital-transformation\"><u>Zero Trust strategy<\/u><\/a>\u00a0survive contact with the real world? Cybersecurity is fluid and dynamic and it must be able to adapt. So how do you assess Zero Trust performance? Think of it as a parallel path in which you continuously check the performance of your systems, their components, and the processes used to manage those components.<\/p>\n<p><strong><b>Authorize<\/b><\/strong><\/p>\n<p>This is the &#8220;go or no-go&#8221; stage when you move your first Zero Trust solutions into production. Everyone from senior leadership down comes together to identify any potential impediments. You want NO surprises at this point.<\/p>\n<p><strong><b>Monitor<\/b><\/strong><\/p>\n<p>All that\u2019s left to do is refine, improve, and make sure it doesn\u2019t break going forward. Remember, re-use and re-purpose existing policies when possible, and include all stakeholders when considering strategy pivots. This is also the time to examine external threat intelligence and the role it will play in your established Zero Trust structure.<\/p>\n<p><strong><b>How to make Zero Trust sticky<\/b><\/strong><\/p>\n<p>It\u2019s all about compound gains. A little goes a long way, and while security architects might be tempted to prove their worth by launching the first-ever fully loaded bells-and-whistles Zero Trust infrastructure &#8212; the weight of change would cause the venture to implode in on itself. Instead, slow, and steady improvements win the race. To summarize how to look at your Zero Trust strategy is to quote famed coach and leadership legend John Wooden:<\/p>\n<p>&#8220;When you improve a little each day, eventually big things occur&#8230; Not tomorrow, not the next day, but eventually a big gain is made. Don\u2019t look for the big, quick improvement. Seek the small improvement one day at a time. That\u2019s the only way it happens &#8212; and when it happens, it lasts.&#8221;<\/p>\n<p><strong><b>About DT Asia<\/b><\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>\n<p>Source: <a href=\"https:\/\/betanews.com\/2022\/10\/16\/7-key-considerations-zero-trust\/\"><u>https:\/\/betanews.com\/2022\/10\/16\/7-key-considerations-zero-trust\/<\/u><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>When we look at Zero Trust, it helps to take a step back. The internet is flooded with articles, hot takes, and it\u2019s all too easy to get caught up in the hype. We run the risk of going too fast and missing important fundamentals<\/p>","protected":false},"author":1,"featured_media":11662,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-11659","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/11659","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=11659"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/11659\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/11662"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=11659"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=11659"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=11659"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}