Kelby Shelton, Splunk security solutions engineer. Source: Splunk
Zero trust is critical in protecting organizations in an increasingly permissionless world and organizations need to evolve the way they approach incident response to incorporate identification and automation to protect their data and their networks, according to Splunk.
“We require new capabilities and new strategies for our security teams. Response has to be effective, yet very precise,” Kelby Shelton, a Splunk security solutions engineer, said during a keynote at the recent Black Hat USA 2022 event.
Those in the cybersecurity field are more likely to prioritize protecting company assets and users, however, “in the past few years, there have been a myriad of factors eroding what we consider a traditional network architecture,” as companies are continuing to shift to remote work, thus shifting the way companies oversee security, he noted.
The 5 Pillars of ZTAEvolving the way companies think about their networks, Shelton continued, comes down to categorization for zero-trust access (ZTA) – pillars of identity, devices, network, applications, and data. Businesses can mature these pillars independently as their security controls grow to develop sophisticated amounts of visibility, analytics, automation, and governance.
That last one is an important component of automation in a zero-trust landscape, which mends analytics and automation as one for continuous enforcement, authorization, and automated remediation, Shelton said.
“That means we don't just let someone in and then we're done evaluating them, even if that user or system has the right to be on the network and they're accessing the right application,” Shelton explained. “We have to revoke access when that unwanted behavior occurs before things get out of hand. So the ultimate kind of panacea is that our analytics and our automation continuously work together to ensure that access is continuously allowed and revoked across those five pillars."
Automation in a Zero-Trust LandscapeShelton touted Splunk's security orchestration, automation, and response (SOAR) platform throughout his keynote as an example of a security program that automates response actions in harmony with zero trust. Dynamic group membership, automatically applying access controls, and following continuous integration and continuous delivery (CI/CD) models, all contribute to automation in a zero-trust landscape.
“Through automated detection, investigation, and response, we can help respond to security threats faster,” Shelton said.
“I don't know about you, but I'd be hesitant to continuously disable users, continuously quarantine machines, continuously block users from accessing the applications they need to do to do their job,” he said, adding, “when it comes to zero trust, we have to start thinking about response a little bit differently.”
Comments