6 ms·
These things are part of the basic tenets [0] of the NIST's Zero Trust Architecture [1], which has become an important cybersecurity target for enterprises. 0:
by TriNetra 5y ago
These things are part of the basic tenets [0] of the NIST's Zero Trust Architecture [1], which has become an important cybersecurity target for enterprises.
0: https://aspsecuritykit.net/blog/7-tenets-of-nist-zero-trust-architecture-zta/ https://aspsecuritykit.net/blog/7-tenets-of-nist-zero-trust-...
1: https://csrc.nist.gov/publications/detail/sp/800-207/final https://csrc.nist.gov/publications/detail/sp/800-207/final
- deleted 5y ago[deleted]
- blowski 5y agoMy experience is companies treating security as if it were a competition where having more "security points" than the hacker means you can't be hacked. Which leads to bizarrely wrong trade-offs like "we don't need passwords on the prod database because it's only accessible through the private network". Even worse is "we're on AWS so we have Amazon-level security".
- TriNetra 5y agoThat's actually anti-ZT practice, which clearly requires that you put maximum security controls you can to protect every resource. especially do not assume trust based on network location/perimeter, is very first tenet. But yeah, security in many orgs (regardless of the size), is another item to be ticked, and thus a false sense of security prevails until an incident happens. Eventually, only such orgs will survive and thrive which will be able to defend their resources, in the increasingly hostile online environment with state-backed attackers. Whether this defense comes from individual organizations or their state, or a combination of both, that's something to be seen in the next 5 to 10 years.