Facts About the Zero Trust Security Model

October is Cybersecurity Awareness Month. You've probably seen many articles and content about zero trust and the zero trust security model. With so many different uses for the term, it can be difficult to understand exactly what it is and what it entails.

So, let's take a look at some of the most frequently asked questions about the zero trust security model.

What is a Zero Trust Security Model?

“Zero Trust”has recently become somewhat of a buzzword in the IT industry, but it cannot be viewed as simply a buzzword.
The Zero Trust security model refers to a modern security paradigm in which users or devices (called principals) are given the minimum access rights to network resources required to perform their tasks, based on their role, when acting appropriately.

One of the things we talk about with zero trust is that it completely eliminates the concept of trust. Literally. Nothing is trustedInstead, the zero trust security model is Limit implicit trust based solely on how and where users connect.do.

This implicitly trusts the company laptop in the office to roam freely across the network. Contrast with the perimeter-based security modelMalicious actors can leverage this broad access to expand their attacks and increase damage.

What are some examples of a zero trust security model?

One of the myths about zero trust security is that it's new or unproven. In fact, the zero trust security model has been around for years.

If you've traveled by air in the past few decades, you've likely seen Zero Trust in action.

The National Institute of Standards and Technology (NIST), an authority on zero-trust network architecture, has compared the concept of a zero-trust security model to an airport.

Airports, with their mix of passengers, pilots, airline employees, visitors, and even some malicious actors, resemble a zero-trust security model.
Within the terminal, access is limited because not much is known about who all users and targets are or what their roles are.

To gain access, these users must pass through security screening. Once they are identified and their purpose is confirmed, they can be assigned roles that grant access to more areas of the airport.
For example, pilots, passengers, and airline employees may be granted access to the boarding area, but only passengers and pilots may enter the aircraft, and only pilots may enter the cockpit. If one of these individuals begins to exhibit behavior inconsistent with their role, such as malicious activity attempting to access restricted areas, their access may be restricted or revoked for further security evaluation.

Zero Trust security model in action
The sequential security screening and restricted access protocols in busy airports reflect a zero-trust security model.

What are the benefits of a zero-trust security model?

A common misconception about Zero Trust is that its drawbacks outweigh its benefits. However, most organizations have discovered that a Zero Trust security model offers significant benefits not only in network security but also in compliance and infrastructure operations efficiency.

The Zero Trust security model offers the following benefits:

  • Restrict access to resources – Unlike network security models that provide users with broad access to resources, the zero trust security model grants users the least privileged access to the resources they need to perform their tasks.
    This approach not only limits the resources an attacker can access, but also restricts employee and guest access to sensitive accounting information, patient, and customer data—critical requirements of PCI DSS, HIPAA, and GDPR.
  • Detect and prevent attacks – Attacks that exploit implicit trust, such as when credentials are stolen or device addresses are spoofed, may not be immediately detected by perimeter-based security strategies.
    In a zero-trust security model, patient behavior is continuously monitored against a baseline, helping to identify potential threats and trigger responses.
  • Preventing the spread of attacks The damage from undetected cyberattacks increases as attackers move within a network. A zero-trust security model can reduce the spread of these attacks by automatically restricting or revoking access based on unusual or suspicious behavior.
  • Scale to fit your organization In a zero-trust security model, least-privilege access is granted based on roles and policies, not on a per-user, per-location, or per-device basis. Therefore, roles and policies can be defined once and applied frequently as needed, allowing organizations to more easily scale security as users, devices, and locations grow.

What is a simple zero-trust security model checklist?

Zero trust isn't a single product or solution that can be implemented instantly with a single click. Therefore, I believe adopting a zero trust security model is a challenging task for many organizations.

If you're not sure where to start, the following checklist will help you prioritize.

  • Even if you don't manage the network, Can I see all devices??
  • For users and devices Assign permissionsIs there a consistent way to do this?
  • Are you enforcing security compliance standards before allowing devices on your network?
  • Across the network Role-Based Access Security PolicyAre you implementing it consistently?
  • Can you continuously monitor your users' security posture using all available data?

Ready to learn more about the Zero Trust security model?

Learn more about the Zero Trust security model and how Aruba supports this strategy through the links below.