1-06 NSA:在数据支柱中推进零信任成熟度 15页 2024

VIP文档

ID:72673

阅读量:1

大小:0.79 MB

页数:15页

时间:2025-01-03

金币:10

上传者:人情世故
U/OO/140279-24 | PP-24-1320 | APRIL 2024 Ver. 1.0
National Security Agency | Cybersecurity Information Sheet
Advancing Zero Trust Maturity Throughout the Data
Pillar
Executive summary
This cybersecurity information sheet (CSI) provides recommendations for maturing data
security and enforcing access to data at rest and in transit, ensuring that only those with
authorization can access the data. It further discusses how these capabilities integrate
into a comprehensive Zero Trust (ZT) framework, as described in Embracing a Zero
Trust Security Model. [1] Traditional security approaches have often relied on perimeter
defenses alone to secure networks. Recent events highlight that adversaries who are
successful at gaining a foothold in information systems often readily gain unfettered
access to all data in those systems. By applying the recommendations in the data pillar,
including identifying risks to data, integrating granular data attributes into access control
mechanisms, and monitoring data access and use, organizations will reduce the impact
and consequences of breaches and identify suspect activity earlier in the cyber intrusion
lifecycle.
To protect data, an organization needs to know what data it has and track how it moves
and is accessed inside and outside the enterprise. Tracking data can be a significant
task, so having an automated method for identifying data of value on the network or
performing a data inventory operation is recommended. Data protection ensures that
data is only accessed by authorized entities. Granular control of data not only keeps it
safe within the enterprise, but also ensures that it can be safely shared with other
organizations and partners to achieve interoperability. Implementing these activities will
limit the ability of adversaries to reach targeted data assets. It will also provide visibility
to system managers of compromised assets that require mitigation should adversaries
be successful in their efforts.
资源描述:

当前文档最多预览五页,下载文档查看全文

此文档下载收益归作者所有

当前文档最多预览五页,下载文档查看全文
温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,天天文库负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
关闭