Section 2.16 Zero Trust Flashcards
What is it and what is the goal? TSR & UDT
Zero Trust
Demands verification for every device, user and transaction regardless of its origin
The goal is to achiecve Threat Scope Reduction
To create a zero trust architecture we must use 2 planes.
Control Plane vs Data Plane
Control Plane: The communication used to control and configure a network take place on the Control Plane
Data Plane: The communications used by end users and software to communicate with eachother take place on the Data Plane. The Data Plane contains all of the systems that carry out the work of the organisation
Seperating the control and data plane reduces the likelhood of an attacker being able to reconfigure the network by accessing the control plane
2 key elements
Control plane elements
- Policy Engine: Decides whether to grant access to a resource for a given subject. The Policy Engine uses enterprise policy to grant, deny or revoke access to the resource
- Policy Administator: Responsible for communicating the desicion made by the Policy Engine to the tools on the network that enforce the desicions, known as the Policy Enforcement Point
4 elements
Data Plane elements
SSEP
Data Plane contains all of the systems that carry out the work of the organisation. The core elements are…
- Subject: User who wants to access a reosurce
- Sytem: The system used by the user to access the resource
- Enterprise Resource: User wants to access a file, server or service
- Policy Enforcement Point: Determines whether to allow access - this is the only system that crosses both the control and data plane as it must recieve the instructions from the Policy Administrator to enforce it on the data plane
Policy Desicion Point
Together Policy Engine and Policy Administator are known as Policy Desicion Point
Secure Access Service Edge (SASE)
Closely realted to Zero Trust that brings together networking and security functions - delivers them as an integrated cloud service.
Adds more security measures such as Intrustion Prevention Systems and Data Loss Prevention etc.