Zero trust is a must-have when transitioning to the cloud, former Senior Director at Gartner and Symmetry Systems Chief Evangelist Claude Mandy argues.

Data security vendor Symmetry Systems offers posture management that helps customers find out where their data resides and secure it within their on-premise, private, and public cloud environments, according to Mandy.

From this data protection perspective, he dove into how to navigate zero-trust deployments for on-premise, hybrid, and multi-clouds with SDxCentral in an interview:

SDxCentral: What is cloud transition’s impact on zero-trust deployment?

Mandy: We see the cloud as a big opportunity to actually get zero trust on the things that you care about. But if you aren't doing zero trust and ignoring the opportunity to do that, then you're putting yourself at risk.

So, there are always those two sides of the story. The reason why we say it's an opportunity is the cloud is set up to be able to enforce zero-trust controls at scale across the smallest level of detail if you automate it and put it in place, but if you don't, then it creates all these holes in your environment that you can't rely on your traditional perimeter. Zero trust has almost become something you have to do when you move to the cloud. And it's just the granularity that you have to do it. And the cloud allows you to do that, which is the opportunity that people provide that they wouldn't have had if they were stuck on premise.

SDxCentral: Why should cloud organizations require an accurate assessment and configuration of their cloud-native bi-directional permissions?

Mandy: When you look at our access controls working in the cloud, you essentially can deny everything as a starting point, but then you actually have to open it up and you say: Alright, if someone wants to read this, we have to allow them to read it. If someone wants to access it and do something with it, we have to allow that data to flow the other way. So that kind of bi-directional is really not just the identity but also the resource that you have to work with.

Historically, most of that access control would have just been done on the identity side, or on the resource side, and you wouldn't have had to worry about it. But when everything is opened directly to the internet, and on the cloud, and you can open it up you actually have to think about which way you want to do it. You have to control it on the data side and on the identity side to kind of work through that.

SDxCentral: On the other hand, does the legacy infrastructure make it harder to apply zero trust?

Mandy: It is because the cloud has been architected that you have these controls implicit in the access control and in the network layer that is configurable from a central control piece. [But for] on-premise, you have to not only build all of that, but also you have to either buy the appliances, the network firewalls, etc., or buy technology to overlay that across your environment.

You're still talking about essentially servers, wires, and things when you talk about on-premise, when you talk about the cloud, all of that has been virtualized for you and it's just about configuration. And it's easier to configure something than it is to actually figure out where the wires go and try to make sure that you architected that way.

SDxCentral: In terms of data protection, how does zero trust work differently for cloud and on-premises environments?

Mandy: On-premise, you struggled to get the same kind of concept, [and] you struggled to get that visibility because everything had its own admin panel or control panel to be able to configure things. So you had to go into your individual databases and then try to get the telemetry then pull it somewhere else so that you can see what was in that data.

In the cloud, all of that is centralized so it's a lot easier to enable that telemetry and visibility into what your data is. Because it's a central place, and you've got fully virtualized so you can install. It does come with its challenges, because when you put everything all together, that's when you'd have challenges around scale, talking about terabytes, petabytes, and large amounts of data that you need to manage rather than the individual pieces. The metadata is the same, it was just so spread out that you really didn't know about it on premise.

SDxCentral: How should organizations navigate zero trust for hybrid and multi-clouds?

Mandy: It is a huge challenge. And I think the biggest challenge is that all those multi-clouds [and] hybrid clouds, they all a little bit kind of unique in their own ways. And when it's unique, then you need someone who's an expert in each of those parts of your multi-cloud and hybrid cloud. So the only way, I think to really get around that is to have a level of abstraction, so that you don't need to have a cloud security team for AWS, a cloud security team for your on premise, a cloud security team for your VMware Cloud, [and] a security team for Azure.

You need to be able to get some technology or some engineering that abstracts that away so that you can kind of already know that when you want to implement a feature or a security control and data, it does across all of those. So there's a lot more hygiene pieces that you can work through to make sure that you're not reliant on having individual teams responsible for each of those pieces.

This interview was edited for length and clarity.

Photo: Symmetry Systems Chief Evangelist Claude Mandy. Source: Symmetry Systems