Zero Trust Model of Cyber Security

Ethan Smith 1 Reputation point
2022-08-13T11:14:55.39+00:00

Hy,

I have a question about why companies are moving to a Zero Trust Model of cyber security.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
{count} votes

1 answer

Sort by: Most helpful
  1. Alistair Ross 7,466 Reputation points Microsoft Employee
    2022-08-15T09:22:46.223+00:00

    Hello @Ethan Smith

    Here is our Zero Trust essentials e-book which explains the principals. The reason for moving to zero trust is that data, users and corporate environments don't sit behind a firewall, but have evolved to sit off-premises, in the cloud and across hybrid networks. Enterprises only want trusted, verified users to access their data and systems, so zero trust applies the principals to:

    1. Verify explicitly: Ensure without doubt that the user is who they say they are.
    2. Apply least privileged access: If a user becomes compromised or goes rogue, ensure they can do the least amount of damage possible. Do not give them access to systems or data that they do not need to do their job at that point in time.
    3. Always assume breach: Continually monitor your environment and detect and respond to existing and new threats in real time, to reduce the risk to your data, before bad actors get a foothold and compromise your business.
    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.