The past year saw the U.S. government officially support zero-trust adoptions. The White House released a memo in January that looked to move government agencies toward a zero-trust security approach. That was followed more recently by the Department of Defense (DoD) releasing its zero-trust strategy and roadmap.
“The Log4j vulnerability is the latest evidence that adversaries will continue to find new opportunities to get their foot in the door,” the White House wrote in a statement about the zero-trust push. “The zero-trust strategy will enable agencies to more rapidly detect, isolate, and respond to these types of threats.”
The Office of Management and Budget (OMB) memo requires federal agencies to submit a zero-trust implementation plan. It “is about ensuring the federal government leads by example,” acting OMB director Shalanda Young said in a statement.
Following this push, the DoD announced its plans to achieve the department-wide zero-trust implementation by fiscal year 2027. In the release, the DoD refers to zero trust as a framework using security capabilities, including multi-factor authentication (MFA), micro-segmentation, advanced encryption, endpoint security, analytics, and robust auditing to fortify data, applications, assets, and services to deliver cyberresiliency.
The framework can reduce the attack surface, manage risks, and allow secure data-sharing for partnerships while ensuring adversary damage containment and remediation after a device, network, user, or credential is compromised, the department noted.
Commvault CEO Sanjay Mirchandani applauded the DoD for approaching the longer-term threat landscape correctly.
“Data has never been more valuable or more vulnerable to threats from well-funded, relentlessly focused bad actors. This is why, as a former CIO, I believe that data protection must begin before it is compromised with security implicitly built-in, not bolted on. The zero-trust model provides a proactive, thorough framework for ensuring data security and protection based on the assumption that a breach has already happened,” Mirchandani wrote in response to questions.
“Zero trust is a strong framework, but what’s even more important to me is the practical implementation, and more importantly, how the DoD quickly adapts its plan as the threat landscape evolves and intensifies over the next five years. Every day we learn of new zero-day exploits, so the DoD and other organizations need a multi-layered proactive and responsive approach to data protection,” he added.
iboss CEO Paul Martini echoed the importance of zero-trust adoption. “The proliferation of professionalized and nation-state-sponsored cyberattacks should have private businesses and government agencies alike on high alert. In our work-from-anywhere world, in order to prevent potentially catastrophic attacks, organizations need to protect their sensitive data and applications regardless of who is accessing them or where. Migrating to a zero-trust architecture from the traditional network security strategies is a huge step forward for the DoD and one that will help the agency strengthen its overall cybersecurity posture."
Comments