Cisco published a framework for assessing an organization’s trustworthiness that it will use as an agreement of sorts with its customers and suppliers, and it wants other companies to follow suit.

“We’re hopeful that it will help shape the industry’s thinking about what does it mean to be a trusted provider,” Cisco’s Chief Privacy Officer Harvey Jang said. “What’s challenging is there’s no consistent standard.”

The New Trust Standard provides an outline for customers of how Cisco will manage their data and maintain their privacy. Cisco will also require all of its suppliers and vendors (Jang puts this number at upwards of 3,000) to adhere to this standard.

Cisco also this week signed on to the Trusted Cloud Principles initiative, which includes cloud giants Amazon, Microsoft, and Google, and pledged to advocate for data privacy and human rights protections in the cloud era.

Trust becomes increasingly important as more organizations move to hybrid work models and collect a growing amount of customer data, Jang said. Meanwhile, as cyberthreats increase, customers want assurances that businesses will not only keep their data secure, but also respect their privacy and provide transparency as to how they collect and use this data and what potential risks they face.

In addition to the New Trust Standard, Cisco also released its Cisco 2021 Consumer Privacy Survey. This survey, which included 2,600 respondents across 12 countries, also influenced the framework for building trust.

“We’re trying to put together what we’ve learned over the years from our thousands of enterprise customers — what are they demanding, and what’s the new standard for trust,” Jang said.

Cisco IDs 5 Elements of Trust

To this end, Cisco identified five elements that it says are critical to earn and maintain customers’ trust. These elements span people, processes, and technology and start with a zero-trust architecture.

“One of the core tenants of our new standard is the zero-trust architecture,” Jang said. “That’s not unique to Cisco. You’re seeing this trending around security overall.”

The pendulum has swung from implicitly trusting known systems and vendors, to trust but verify, and now has shifted to zero trust, he explained. Zero trust isn’t one technology, but rather a framework to ensure that only continuously verified users and devices are allowed access to corporate resources and restrict data on a least-privilege basis.

“I’m going to assume that you are a bad actor, and I’m going to put in the controls to make sure that you’re not,” Jang said.

In addition to zero trust, the other elements of the Cisco Trust Standard include trusted supply chain, data governance to ensure data is secured and access is limited, transparency about what data companies collect and how they use it, and certifications and regulatory compliance that includes third-party audits.

Transparency is a good place for organizations that want to implement their own trust standards, Jang said. “Understanding the data you’re collecting, what you’re doing with it, and the risks that that dataset poses — not just looking at your intended use,” he added. “Most companies are lawful, and they have good motives, but you have to take it one step further and think about what are some of the unintended consequences of what you’re doing?”

Jang said when he works with engineers he asks them to imagine that their worst enemy has access to the dataset. “What could they do with this data to harm you, to embarrass you? You almost think like a bad actor.”