3 ms·
It also wouldn't hurt to move away from the "network security" model to a "zero trust network" model, where each computer is secured against everyone else in th
by higherpurpose 11y ago
It also wouldn't hurt to move away from the "network security" model to a "zero trust network" model, where each computer is secured against everyone else in the internal network, just like it would be against the Internet, and the users have very limited privileges to only allow them to do the job they are required to do.
http://blogs.wsj.com/cio/2014/04/24/google-cio-enterprises-should-build-zero-trust-infrastructure/ http://blogs.wsj.com/cio/2014/04/24/google-cio-enterprises-s...
https://static.googleusercontent.com/media/research.google.com/en/us/pubs/archive/43231.pdf https://static.googleusercontent.com/media/research.google.c...
- tptacek 11y agoThat's the logical extreme of the "network segmentation" bullet I listed above. The problem with endpoint security and internal trust is that the endpoints aren't the most valuable goal on the internal network; we attack them because they're pivots to internal applications, which are the most valuable goal. So making it harder to compromise an individual desktop from within an internal network doesn't really do much. Making it harder for an arbitrary desktop to reach the document management server, though, does make a difference.