As zero-trust security gains traction, Thrive CTO Michael Gray underlined the importance of implementing multi-factor authentication (MFA) as one of the key zero-trust principles for CISOs and recommends starting the journey with asset identification and management.
MFA is an important security control, which is more than “SMS code to a phone or a push message through an app,” Gray told SDxCentral. “It's a way to confirm somebody's identity and the risk around that identity.”
He argues MFA needs to be dynamic. “Trying to bring as many factors together is a huge part of zero trust, which is how many different factors about this entity can I bring together to either confirm their identity or decide that it's too risky of a login and deny it.”
Including adopting these conditional-access policies, Gray noted there is a lot IT teams can do to combat MFA fatigue. “There's gotta be something about that attacker's behavior that is allowing them to send that push message 50 times an hour.”
Other important zero-trust principles CISOs should adhere to include all networks should be treated as untrusted; end users should only have the least privilege that they need to execute the tasks and be removed when it’s no longer required; access should only be granted to trusted devices, which must be checked at every access point; and application access policies must be in place, Gray said.
Thrive CTO on Zero Trust Adoption HurdlesGray defines zero trust as “understanding your trusted identities and your most critical data and the flow between those two things.” As zero trust enters maturity, Gray expects it will reach widespread adoption in two years.
However, “there are some much larger hurdles before implementing zero trust and that is having a good handle on your data,” he argues. “If you have a lot of legacy data on legacy systems, implementing zero trust is going to be very, very difficult.”
Gray recommends the first step of the zero-trust journey should be asset identification and management, which is the baseline for the strategy.
“In order to secure something and trust something, it needs to know what that something is. And if you can't tell me the identities and the critical assets then it's almost impossible to implement zero trust,” he concluded.
Comments