Zero Trust: Origins and Evolution
摘要
In this chapter, we will introduce the concept of Zero Trust, discuss the importance of strategy, provide some history about its origin and development, address principles and misconceptions surrounding Zero Trust, and conclude the chapter with guidelines for successful Zero Trust deployments. The descriptions should not require a cybersecurity certification to understand but a basic grasp of the cybersecurity triad (confidentiality, integrity, and availability) is recommended. The cybersecurity triad (CIA) shapes how cyber professionals assess each risk. Confidentiality involves keeping sensitive data secret or private. Integrity ensures that data is trustworthy and free from unauthorized tampering. Availability means that data, networks, and services must function and be accessible to authorized users. All three of these principles guide cybersecurity teams in addressing risk, and when all three principles are satisfied, the security of an organization improves. As you explore the rest of this book, we will examine Zero Trust and PAM principles, with the CIA triad consistently driving risk identification and mitigation.