IBM Security today rolled out several zero-trust security updates including a secure access service edge (SASE) partnership with Zscaler, new zero-trust use case blueprints, and a software-as-a-service (SaaS) version of IBM Cloud Pak for Security.

“Zero trust is not new to the market, but for us, it’s been about focusing on outcomes,” said IBM Security VP Aarti Borkar. This is why the vendor developed four zero-trust blueprints, rather than bundled security products, she explained.

“We’re talking about security outcomes with zero trust for use cases that are the most common pain points in our clients today, and they go across four areas,” Borkar added. “Customer privacy, securing the hybrid cloud as people move to the cloud, focusing on protection of the remote workforce, and then reducing insider threats.”

Securing remote workers during the pandemic has been a top zero trust use case over the past year, and this has fueled demand for SASE as a means to deliver security closer to users and devices.

Zscaler SASE Partnership

IBM’s Zscaler partnership fits into its hybrid-work blueprint, and it also marks IBM’s move into SASE.

The Zscaler SASE partnership integrates Zscaler Private Access, which provides zero trust network access to private apps, and Zscaler Internet Access, the vendor’s secure web gateway software, with several IBM Security technologies and services. These include IBM’s identity and access management, cloud and mobile security, security information and event management, and threat management, detection, and response.

Customers can buy a fully managed SASE service, or IBM can play more of an advisory role and help users plan and deploy a SASE architecture.

Even before the SASE deal, Zscaler partnered with IBM, “and we’ve seen a lot of traction in a whole host of accounts, across geographies — Europe, Asia-Pacific, and North America — so we selected Zscaler to have a much deeper relationship across our software services,” Borkar said. “They are clearly a leader in the space, and they’re doing some amazing, innovative work that was recognized by our clients.”

IBM Zero Trust Security Blueprints

Zscaler also plays a role in one of the new IBM zero trust blueprints: specifically, its hybrid workforce blueprint.

These blueprints help customers build a framework for their security programs using the core principles of zero trust: least privilege access; never trust, always verify; and assume breach. They include both product and process recommendations, as well as guidance on how to integrate technologies as part of a zero trust architecture.

Dow Chemical is an early customer that worked with IBM Security and Zscaler to provide secure, remote access to all of its locations and access to its applications across a hybrid IT environment.

“Dow brought us in to talk zero trust through our zero trust advisory services, and their No. 1 use case was remote workforce,” Borkar said. “And you can’t have a remote workforce conversation without the fusion of SASE along with identity, among other things.”

IBM deployed its Zscaler-based SASE service for Dow Chemical, and that company’s CISO Mauricio Guerra will discuss how this has improved Dow’s security posture during the IBM Think security keynote on May 11. “With a mobile workforce and data residing everywhere, the Internet has become our primary network,” Guerra said in a statement. “Embracing a zero-trust architecture enables us to add new capabilities and strengthen security.”

IBM’s other three zero trust blueprints focus on preserving customer privacy, securing hybrid-cloud environments, and reducing the risk of insider threats.

Using the privacy blueprint, organizations can enforce limited and conditional access to all data and help reduce exposure in the event of compromise. The technology involved in this blueprint generates insights into data usage and privacy risk, and it can enforce security policies to keep data usage aligned with its purpose. Additionally, it can detect and automatically respond to risk and compliance issues. Security tools include IBM Cloud Pak for Security, which now includes data protection capabilities from IBM Security Guardian.

The hybrid cloud blueprint capabilities help enable continuous compliance, reporting, and response. They monitor for cloud misconfigurations and enforce consistent security policies across clouds and cloud workloads.

And finally, the insider threat blueprint suggests technologies and processes to manage insider threats.

“We’re seeing close to 50% increase in insider threats in just the last two years,” Borkar said. This blueprint is designed to detect user behavior anomalies, enforce security policies with automation, and insulate data. It also includes new mobile threat detections from IBM Security MaaS360 with Watson-powered user behavior analytics, and it’s delivered as a part of IBM Cloud Pak for Security.

SaaS Cloud Pak for Security

Additionally, IBM today released a SaaS version of its Cloud Pak for Security.

IBM started shipping an on-premises and cloud version in late 2019. It’s a containerized security platform that comes pre-integrated with Red Hat OpenShift.