CISA Zero Trust Maturity Model
cisa.gov
CISA Zero Trust Maturity Model
1–10 of 22 posts
Re: CISA Zero Trust Maturity Model
#2Re: CISA Zero Trust Maturity Model
#3We have thousands of pages of frameworks and NIST guides and the people in charge, especially in the private sector, are free to neglect or ignore them with impunity because apparently regulators don’t care and the market doesn’t care, so why should they?
It’s like we have these brilliant cryptographers working on technical advancements that I can barely grasp, and the people (management) in charge of putting their work to use can’t be bothered with basic patch management.
The whole landscape of practical cybersecurity feels very hopeless to me.
Re: CISA Zero Trust Maturity Model
#4I perused the draft and was surprised by my jaded reaction: Great! More effort put into detailed cybersecurity strategies for the likes of OPM, T-Mobile, and Equifax to ignore. We have thousands of pages of frameworks and NIST guides and the people in charge, especially in the private sector, are free to neglect or ignore them with impunity because apparently regulators don’t care and the market doesn’t care, so why…
“Why do you wanna make that change? It’s expensive!”
“Because it says so right here, sir”
That “official” guidance can go a long way.
Re: CISA Zero Trust Maturity Model
#5I perused the draft and was surprised by my jaded reaction: Great! More effort put into detailed cybersecurity strategies for the likes of OPM, T-Mobile, and Equifax to ignore. We have thousands of pages of frameworks and NIST guides and the people in charge, especially in the private sector, are free to neglect or ignore them with impunity because apparently regulators don’t care and the market doesn’t care, so why…
Re: CISA Zero Trust Maturity Model
#6I perused the draft and was surprised by my jaded reaction: Great! More effort put into detailed cybersecurity strategies for the likes of OPM, T-Mobile, and Equifax to ignore. We have thousands of pages of frameworks and NIST guides and the people in charge, especially in the private sector, are free to neglect or ignore them with impunity because apparently regulators don’t care and the market doesn’t care, so why…
Re: CISA Zero Trust Maturity Model
#7I perused the draft and was surprised by my jaded reaction: Great! More effort put into detailed cybersecurity strategies for the likes of OPM, T-Mobile, and Equifax to ignore. We have thousands of pages of frameworks and NIST guides and the people in charge, especially in the private sector, are free to neglect or ignore them with impunity because apparently regulators don’t care and the market doesn’t care, so why…
Come work in healthcare - if you are at one of the larger insurance orgs (UHG, Anthem, Humana) or hospital networks (HCA, Dignity, etc) you are locked into a world of this model making your life the most difficult imaginable. Need vendor support? Hope you like watching them work over webex as they wont have any access to any of your servers. Need a VPN to tunnel data across? Yeah good luck with that it'll take at lea…
I'm a security pro and I rejoice in secure systems, but swinging the pendulum to the other side is bad too.
Re: CISA Zero Trust Maturity Model
#8https://doublepulsar.com/the-hard-truth-about-ransomware-we-...
> The truth is, while governments are pushing frameworks such as Zero Trust, the amount of orgs who successfully implement these are… not many. Many companies can barely afford to patch SharePoint, let alone patch the the tens of thousands of application vulnerabilities shown in a vulnerability management program, and really struggle with accurate asset lists. … > My concern, for years, has been that ransomware gangs have not only closed the loop on monetization, they are also acquiring so much income they are becoming a bigger operational threat than some states. > > To give an example, one ransomware group receiving a $40m payment for attacking a cybersecurity insurance company gives the attackers more budget to launch cyberattack than most medium to large organizations have to defend against attacks in total. And that’s just one attack, from one group, that barely made the news radar of most people. > > The payment amounts are increasing, the frequency is increasing, the sophistication is increasing.
Re: CISA Zero Trust Maturity Model
#9Earlier quoted context omitted.
Come work in healthcare - if you are at one of the larger insurance orgs (UHG, Anthem, Humana) or hospital networks (HCA, Dignity, etc) you are locked into a world of this model making your life the most difficult imaginable. Need vendor support? Hope you like watching them work over webex as they wont have any access to any of your servers. Need a VPN to tunnel data across? Yeah good luck with that it'll take at lea…
Agreed, be careful what you wish for. When I was a consultant at Red Hat I worked with a lot of customers in this boat. We had to jump through absolutely absurd hoops that made a two day job take weeks. I'm a security pro and I rejoice in secure systems, but swinging the pendulum to the other side is bad too.
I think that's the ultimate goal of "zero trust," but maybe I'm naive
Re: CISA Zero Trust Maturity Model
#10I perused the draft and was surprised by my jaded reaction: Great! More effort put into detailed cybersecurity strategies for the likes of OPM, T-Mobile, and Equifax to ignore. We have thousands of pages of frameworks and NIST guides and the people in charge, especially in the private sector, are free to neglect or ignore them with impunity because apparently regulators don’t care and the market doesn’t care, so why…