Zero Trust
An important concept to consider is Zero Trust, which uses the approach of never trust, always verify; this concept relates to thinking beyond traditional network perimeter-based security and adopting a holistic approach to security.
Zero Trust is not a service or solution but a wider-thinking security strategy and framework to be adopted, and works on the notion of ensuring compliance and securing access at the resource and no longer the location or network the resource is on; we must NOT assume trust because of the resource's network or location.
The Zero Trust framework is built upon the following foundational principles:
- Assume breach.
- Verify explicitly.
- Use least-privilege access (Just In Time (JIT), and just enough access).
In this new world of hybrid work where organizations' traditional firewalls and security service-controlled network perimeters have vanished due to remote working, we must now consider identity as the new perimeter...