4 ms·
Many organisations do/used to operate where if a device was in a site (for example), it was trusted to access resources. SO in this scenario, using their defini
by PLG88 4y ago
Many organisations do/used to operate where if a device was in a site (for example), it was trusted to access resources. SO in this scenario, using their definition of zero trust is more secure.
The issue (in my opinion) is that ZT is an overused term to describe simple security best practice (e.g., you should never just trust the client as you say).
I wish more people were stricter on usage for zoer trust, e.g., mandating a software-defined perimeter ideally with outbound only connections so that resources can be reach over the internet only by explicitly trusted users and endpoints, a whole set of external network attacks become impossible.