Example: tourism industry

Zero Trust Architecture and Solutions

Issue 1 Zero Trust Architecture and Solutions 2 In the era of cloud computing and big data, the network security perimeter is gradually disintegrating, and internal and external threats are intensifying, leading to the failure of the traditional perimeter-based security Architecture , therefore the zero Trust security Architecture comes into being. The zero Trust security Architecture establishes a dynamic digital identity-based perimeter with four key capabilities, which are identity-based schema, resource secure access, continuous Trust evaluation and adaptive access control.

with today’s network threats. A new network security architecture is needed to cope with the modern and complex enterprise network infrastructure, and to cope with the increasingly severe network threat situation. Zero Trust Architecture emerges in this context and is an inevitable evolution of security thinking and security architecture. 1.1.

Tags:

  Network

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Zero Trust Architecture and Solutions

1 Issue 1 Zero Trust Architecture and Solutions 2 In the era of cloud computing and big data, the network security perimeter is gradually disintegrating, and internal and external threats are intensifying, leading to the failure of the traditional perimeter-based security Architecture , therefore the zero Trust security Architecture comes into being. The zero Trust security Architecture establishes a dynamic digital identity-based perimeter with four key capabilities, which are identity-based schema, resource secure access, continuous Trust evaluation and adaptive access control.

2 It helps enterprises realize a new generation network security Architecture with comprehensive identity, dynamic authorization, risk measurement, and management paper begins with the background, definition and development history of zero Trust security, then proposes a general zero Trust reference framework, and takes Qi An Xin Zero Trust Security Solution as an example to interpret the application scheme of zero Trust reference framework, finally discusses the zero Trust migration methodology, and puts forward the migration ideas with defining the vision, planning first and constructing step by IntroductionThe enterprise network infrastructure is becoming more and more complex with gradually blurred perimeter.

3 The digital transformation has driven the rapid evolution of information technology, new IT technologies such as cloud computing, big data, Internet of Things and mobile internet have brought new productivity to all industries, in the meantime, they also have brought great complexity to the enterprise network infrastructure. On one hand, the adoption of cloud computing, mobile internet and other technologies makes enterprise s staff, businesses and data go outside of the enterprise s digital walls; on the other hand, the open and collaborative demands for new technologies, such as big data and Internet of Things, lead the outside staff, platforms and services pass through the digital walls and go into the enterprises.

4 The modern enterprise network infrastructure has no single, well-recognized and clear security perimeter anymore, in other words, enterprise security perimeter is gradually disintegrating, and the traditional perimeter-based network security Architecture and Solutions are found difficult to adapt to modern enterprise network Trust Architecture and SolutionsZero Trust Architecture and Solutions 2 Research from Gartner Market Guide for Zero Trust network Access 14 About Qi An Xin Group 21 Zero Trust Architecture and Solutions is published by Qi An Xin Group.

5 Editorial supplied by Qi An Xin Group is independent of Gartner analysis. All Gartner research is 2020 by Gartner, Inc. All rights reserved. All Gartner materials are used with Gartner s permission. The use or publication of Gartner research does not indicate Gartner s endorsement of Qi An Xin Group s products and/or strategies. Reproduction or distribution of this publication in any form without prior written permission is forbidden. The information contained herein has been obtained from sources believed to be reliable. Gartner disclaims all warranties as to the accuracy, completeness or adequacy of such information.

6 Gartner shall have no liability for errors, omissions or inadequacies in the information contained herein or for interpretations thereof. The opinions expressed herein are subject to change without notice. Although Gartner research may include a discussion of related legal issues, Gartner does not provide legal advice or services and its research should not be construed or used as such. Gartner is a public company, and its shareholders may include firms and funds that have financial interests in entities covered in Gartner research. Gartner s Board of Directors may include senior managers of these firms or funds.

7 Gartner research is produced independently by its research organization without input or influence from these firms, funds or their managers. For further information on the independence and integrity of Gartner research, see Guiding Principles on Independence and Objectivity on its In addition, the network security situation is not optimistic. External attacks and internal threats are intensifying, organized attacks, weaponized attacks, and advanced attacks with data and services as targets can still easily find loopholes that break through the perimeter of the enterprise, while internal threats such as unauthorized access to internal businesses, employee mistakes and intentional data theft have been popping out.

8 Faced with such severe security challenges, the industry s security awareness has been paid more attention, and the security investment becomes also higher. However, the security effect is not that satisfactory, and security incidents emerge one after another. What is the root cause of the failure for the traditional security Architecture ? The fundamental basis of security is to deal with risks, and the risks are closely related to loopholes . What loopholes lead to the failure of traditional security Architecture ? The answer is Trust . The traditional perimeter-based network security Architecture assumes that the people and devices in the internal network are trustworthy, therefore the security strategy is to build the digital walls of the enterprise, and the security products such as firewalls, WAF, IPS are sufficient to protect the perimeter of the enterprise network .

9 However, one should assume that there are always undiscovered loopholes in the network systems, there are always discovered but unpatched loopholes in the systems, the systems have always been infiltrated and that the insiders are always unreliable. These four always assumptions overturn the technical methods of traditional network security by segmenting network and building the walls, and overturn the abuse of Trust under the perimeter security Architecture , which the perimeter-based security Architecture and Solutions have been found difficult to deal with today s network new network security Architecture is needed to cope with the modern and complex enterprise network infrastructure, and to cope with the increasingly severe network threat situation.

10 Zero Trust Architecture emerges in this context and is an inevitable evolution of security thinking and security Definition of Zero TrustZero Trust Architecture has been developing rapidly and been gradually mature, while different versions of the definition are described in different dimensions. In the book Zero Trust Networks: Building Secure Systems in Untrusted Networks, Evan Gilman and Doug Barth definite that a zero Trust is built upon five fundamental assertions:1 The network is always assumed to be hostile. External and internal threats exist on the network at all times.


Related search queries