While zero trust is a cybersecurity concept that many organizations strive to achieve, it's not always easy.
Cybersecurity provider Trellix says it's trying to be part of the solution with its new Zero Trust Strategy (ZTS) offering, which is designed to help organizations implement a zero-trust architecture. The platform includes Trellix's extended detection and response (XDR) capabilities along with a series of partner integrations for securing identities, devices, networks, data and workloads across on-premises and cloud environments.
ZTS itself is composed of a series of existing technologies that are now being combined into a packaged offering.
“Trellix's Zero Trust Strategy Solution is not a new technology but a comprehensive package of integrated technologies and capabilities working in unison to address each of the five pillars of zero trust, helping organizations successfully adopt, transition, and mature to a Zero Trust framework,” Harold Rivas, CISO at Trellix told SDxCentral.
What's inside Trellix ZTSTrellix ZTS specifically maps to the five pillars defined in the zero-trust maturity model published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This includes capabilities for managing identities, securing endpoints, micro-segmenting networks, controlling data access and protecting application workloads.
At the core of the new bundle is the Trellix XDR platform, which has native controls across endpoint, email, network, cloud and data security. The XDR is also coupled with integrations with leading identity providers and workload security providers. Rivas said that software components include Trellix Helix security orchestration automation and response (security, orchestration, automation, response (SOAR)) platform, Endpoint security, network detection and response (NDR), data security and the cloud workload protection platform (CWPP).
ZTS maps to the five zero-trust pillars in the following ways:
- Identities: To help protect identities Trellix partners with leading identity vendors like Okta.
- Devices: Trellix XDR alongside its endpoint security provides visibility and control for devices.integrated suite of prevention, detection, response, and forensic endpoint and mobile security technologies provide organizations with visibility and control over all devices
- Networks: Trellix NDR fits in to help solve this pillar of zero trust.
- Data: Trellix Data Security technologies already provide numerous data controls. Trellix also provides native CWPP features and has partnered with SkyHigh Networks to extend its DLP offering to cloud environments. The partnership enables Trellix to cover additional use cases like cloud native application protection platform (CNAPP), cloud access security broker (CASB) and software-as-service security across hybrid environments.
- Applications and workloads: Trellix secures workloads across on-premises and cloud using machine learning, containment, VM anti-malware, file monitoring, and microsegmentation.
According to Rivas, a common challenge with zero trust is where to begin.
“It’s such a large undertaking many organizations struggle to know what to do first,” he said.
Rivas said that the path to XDR mirrors the requirements for zero trust, namely, gaining visibility across the organization’s infrastructure, which XDR can do.
“Start with visibility, assess your posture, and make informed decisions for how and where to mature zero trust -- understanding it’s not going to happen with one effort and will take refinement of controls and policies over time; it’s an ongoing endeavor,” Rivas said.
Comments