惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
宝玉的分享
宝玉的分享
量子位
Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
J
Java Code Geeks
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
Blog — PlanetScale
Blog — PlanetScale
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
S
SegmentFault 最新的问题
B
Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
小众软件
小众软件
The Cloudflare Blog
Y
Y Combinator Blog
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
IT之家
IT之家

MeriTalk

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Reinventing FedRAMP in the Age of AI Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report
Comply-to-Connect is Key to Zero Trust for DoD
MeriTalk Sta · 2023-02-23 · via MeriTalk

By Melissa Trace, Vice President, Global Government Solutions at Forescout Technologies

Research from Forescout’s Vedere Labs reveals that government organizations have the highest percentage of devices with risk. Between the explosion of remote work, the ongoing ransomware epidemic and the fact that the number of non-traditional assets – such as IoT, OT and IoMT – outnumber the volume of traditional IT assets, agencies are well aware of the need to evolve the cybersecurity of government networks. In fact, relative to the private sector, government is reportedly leading the charge in the adoption of zero trust.

The allure of zero trust methodology is the ability to restrict access to data resources by assessing user-resource connection requests in the most granular method possible. Agencies turn to the primary zero trust authority, Draft NIST Special Publication (SP) 800-207: Zero Trust Architecture  (NIST SP 800-207), which provides the following steps for introducing zero trust to a perimeter-based architected network:

  1. Identify actors on the enterprise;
  2. Identify assets owned by the enterprise;
  3. Identify key processes and evaluate risk associated with executing them;
  4. Formulate policies for the zero trust architecture candidate policy enforcement point (PEP);
  5. Identify candidate PEP solutions;
  6. Begin deployment monitoring; and
  7. Expand the zero trust architecture.

The very first steps are an undertaking for an organization as comprehensive as the Department of Defense (DoD). The DoD Information Network (DoDIN) spans thousands of networks, each with thousands of connected devices and connected systems. Simply knowing all of the IT assets on the DoDIN has always been a challenge.

Comply-to-Connect Leverages Zero Trust Principles for the DoD

The DoD launched Comply-to-Connect (C2C), one of the largest government cybersecurity efforts globally, to effectively boost its cybersecurity posture across the enterprise. C2C leverages zero trust’s least privilege principles to protect access to data resources and assets.

C2C provides the foundation of the DoD’s zero trust journey and is the next step in the evolution of security throughout the DoDIN at both the classified and non-classified levels. A major distinction between C2C and previous security programs is that C2C seeks visibility of all assets (both traditional and non-traditional). Whereas other enterprise security solutions focus on a subset of DoDIN-connected devices, C2C applies to all categories of DoDIN-connected devices: workstations/servers, mobile devices, user peripherals, platform IT devices, IoT devices, and network infrastructure devices.

Further, DoD’s C2C policy allows teams to authenticate the security posture for the endpoint of each resource prior to granting access to the network. Before access is given, all devices are examined to ascertain compatibility with organization policy. In accordance with zero trust, systems and devices are, then, only granted access to appropriate network areas. All connected devices are continually monitored with the ability to address any cyber-related discrepancies through automated action within the C2C framework.

The two main objectives of C2C are:

  1. C2C fills existing capability gaps in currently fielded enterprise security solutions through complete device identification, device and user authentication, and security compliance assessment.
  2. C2C automates routine security administrative functions, remediation of noncompliant devices and incident response through the integration of multiple management and security products and continuous monitoring.

The Importance of Visibility and Monitoring

Visibility and monitoring are prerequisites to DoD’s zero trust “never trust, always verify” authentication and compliance policies. They are also at the core of every government journey to zero trust, whether they are just beginning or have attained some level of maturity.