In the 15 years since zero trust was first conceptualized, the framework has evolved significantly. Anand Oswal, SVP and GM of network security at Palo Alto Networks, sheds light on the latest updates, implementation challenges, and the ultimate objectives of zero trust.
“Zero trust is the most abused word in cybersecurity,” Oswal told SDxCentral. “I think zero trust is a journey, is not a product. … It's a framework. It's an architecture that customers want to get to.”
Oswal emphasized the principle of zero trust as a framework where no entity — whether a user or device — is trusted by default, regardless of location or network. “I don't trust anything. That is the principle of zero trust, and that's across who the user is, all the devices, what they're accessing it from, what they're trying to access. And then, once you allow that connection, you want to secure it continuously, inspect it continuously. It's not like one and done.”
This approach is crucial in maintaining security across various networks and devices, from corporate laptops to personal smartphones, whether users are at home, in the office, or on a plane.
“It's hard, because over the years, customers have built complicated stacks, point products, and different solutions, so now they're trying to harmonize and normalize it, which is a journey for them,” Oswal said.
It requires a platform-centric approach, he added. “That's where our customers are gravitating toward. They all want to simplify and unify cybersecurity, and that is only possible through a platform-centric approach.”
Zero-trust guide update One of the latest updates is that the National Institute of Standards and Technology (NIST)'s recently released the fourth version of its preliminary draft practice guide on zero-trust architecture for public comment. The release is part of the National Cybersecurity Center of Excellence’s (NCCoE) ongoing efforts to provide comprehensive guidelines and best practices for implementing zero-trust frameworks across diverse enterprise environments.
NIST partnered with 24 vendors for the publication, including Amazon Web Services (AWS), Broadcom (VMware), Google Cloud, IBM, Palo Alto Networks, Microsoft, and Zscaler, offering 17 sample zero-trust implementations. These examples are designed to address the complex security needs of modern enterprises, which often span on-premises and multiple cloud environments.
The goals of the zero-trust journey The end stage of the zero-trust journey, according to Oswal, is a platform that delivers consistent security policies for any user, accessing any data, from any device or location.
“They are the foundation. And then, of course, each of the components of the platform [should be] best in class. And you need to have all the right policies, the best practices, the alerts, the mechanisms to get there,” Oswal said, comparing the ongoing battle between security professionals and cybersecurity adversaries to a “Tom and Jerry game,” where security teams must constantly stay ahead of attackers who only need to succeed once.
Cybersecurity “is the only industry that has an active adversary, right? So it's a constant game,” Oswal said.
Comments