{"id":5654,"date":"2020-10-05T18:55:26","date_gmt":"2020-10-05T16:55:26","guid":{"rendered":"https:\/\/tekmart.co.za\/t-blog\/?p=5654"},"modified":"2020-10-05T18:55:27","modified_gmt":"2020-10-05T16:55:27","slug":"zero-trust-model-zero-trust-network","status":"publish","type":"post","link":"https:\/\/tekmart.co.za\/t-blog\/zero-trust-model-zero-trust-network\/","title":{"rendered":"zero-trust model (zero trust network)"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 2<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>\n<h2 class=\"wp-block-heading\"><strong>The zero trust model is a security model used by\u00a0IT\u00a0professionals that requires strict identity and device verification regardless of the user\u2019s location in relation to the\u00a0network perimeter.<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/cdn.ttgtmedia.com\/rms\/onlineImages\/rouse_margaret.jpg\" alt=\"\"\/><\/figure>\n\n\n\n<p>Posted by:\u00a0<a href=\"https:\/\/www.techtarget.com\/contributor\/Margaret-Rouse\">Margaret Rouse<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/whatis.techtarget.com\/\">WhatIs.com<\/a><\/p>\n\n\n\n<p>Contributor(s): Laura Fitzgibbons<\/p>\n\n\n\n<p>The model is based on the assumption that all users, devices and transactions are already compromised, regardless of whether they&#8217;re inside or outside of the firewall.&nbsp; By limiting which parties have privileged access to each segment of a network, or each machine in a secure organization, the number of opportunities for a hacker to gain access to secure content is greatly reduced. A network that implements the zero trust model is referred to as a zero trust network.<\/p>\n\n\n\n<p>The main tenet of zero trust security is that vulnerabilities often appear when companies are too trusting to individuals or outsiders. Therefore, the model suggests that no user, whether inside or outside the network, should be trusted by default.<\/p>\n\n\n\n<p>The term zero trust was introduced by an analyst at Forrester Research in 2010, with vendors like\u00a0Google\u00a0and\u00a0Cisco\u00a0adopting the model shortly after.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Importance of the zero trust model<\/strong><\/h3>\n\n\n\n<p>The traditional approach to network security is known as the castle-and-moat model. The focus of this concept is that gaining access to a network from the outside is difficult, but once inside, users are automatically trusted. This becomes harder to manage as organizations keep their data distributed across multiple locations, applications and\u00a0cloud services.<\/p>\n\n\n\n<p>The zero trust model acknowledges that focusing only on perimeter security is not effective. Most\u00a0data breaches\u00a0occur when hackers successfully bypass an organization\u2019s\u00a0firewall\u00a0and are then granted authentication into internal systems. Therefore, the zero trust model is a stronger approach to protecting important resources.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Fundamentals of the zero trust model<\/strong><\/h3>\n\n\n\n<p>While there are various technologies and principles that can be used to enforce zero trust security, the basic fundamentals include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Eliminated trust- No user or device should be trusted by default.<\/li><li>Least-privileged access- Users should receive the minimum amount of access necessary.<\/li><li>Microsegmentation- Security perimeters and network components are broken into smaller segments with individual access requirements.<\/li><li>Risk management\u00a0analytics- All\u00a0network traffic\u00a0should be logged and inspected for suspicious activity.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/cdn.ttgtmedia.com\/rms\/onlineImages\/networking-build_a_zero_trust_network-f.png\" alt=\"\"\/><figcaption><strong>Learn the steps you should take to build a zero-trust network and which tools you can use to accomplish them.<\/strong><\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How to implement the zero trust model<\/strong><\/h3>\n\n\n\n<p>Some best practices for\u00a0introducing zero trust security\u00a0to an organization include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Keep network security policies updated, review them for vulnerabilities and test their effectiveness periodically.<\/li><li>Implement multi-factor authentication (MFA) for all users without exception.<\/li><li>Validate all devices that try to log into the network and only allow access to those that meet security standards.<\/li><li>Rely on network segmentation, microsegmentation and perimeter segmentation to secure individual aspects of the network.<\/li><li>Maintain as much visibility as possible throughout the organization to avoid abuse of access that could lead to a data breach.<\/li><li>Review the list of user accesses and administrators frequently.<\/li><\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><a href=\"https:\/\/www.techtarget.com\/contributor\/Margaret-Rouse\"><\/a><strong><a href=\"https:\/\/www.techtarget.com\/contributor\/Margaret-Rouse\">Margaret Rouse<\/a>\u00a0asks:<\/strong><\/p><p><strong>Does your organization prefer the zero trust model over other network security models?<\/strong><\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\"><a href=\"https:\/\/searchsecurity.techtarget.com\/definition\/zero-trust-model-zero-trust-network?_ga=2.235327298.2108807099.1601911192-771408278.1598007830#commenting\"><strong>Join the Discussion<\/strong><\/a><\/h2>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 2<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>The zero trust model is a security model used by\u00a0IT\u00a0professionals that requires strict identity and device verification regardless of the user\u2019s location in relation to the\u00a0network perimeter. Posted by:\u00a0Margaret Rouse WhatIs.com Contributor(s): Laura Fitzgibbons The model is based on the assumption that all users, devices and transactions are already compromised, regardless of whether they&#8217;re inside or outside of the firewall.&nbsp;<\/p>\n<p><a class=\"more-link\" href=\"https:\/\/tekmart.co.za\/t-blog\/zero-trust-model-zero-trust-network\/\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,5,30,3,9,118],"tags":[],"class_list":["post-5654","post","type-post","status-publish","format-standard","hentry","category-datacenter-news","category-engage-the-experts","category-expert-advise-and-opinion","category-industry-news-and-expert-advise","category-tech-definitions","category-zero-trust-model-zero-trust-network"],"_links":{"self":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/5654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/comments?post=5654"}],"version-history":[{"count":1,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/5654\/revisions"}],"predecessor-version":[{"id":5655,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/5654\/revisions\/5655"}],"wp:attachment":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/media?parent=5654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/categories?post=5654"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/tags?post=5654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}