Policy enforcement depends on reliable identity signals
A policy engine can only decide on what it is told, so the quality of its decisions is the quality of its inputs.
If the device state is stale, the group membership has not synchronised or the location is wrong, the decision is confidently incorrect. Zero trust architectures move a great deal of weight onto these signals, which means the plumbing that produces them becomes security-critical in a way it was not before.
More on Zero trust
- Zero trust removes implicit trust in network position, not confidence in colleaguesIt was never about the people
- Continuous evaluation means decisions can changeYes is not for ever
- Zero trust does not remove network controlsKeep the fence
- Service-to-service traffic needs identity tooMachines need names too
- Device trust should match what is actually measuredOnly what the probe touched
- Policy engines create critical dependenciesOne box, every door
