Policy engines create critical dependencies
If every request is checked against a central policy service, that service is now load-bearing for everything.
When it is slow, everything is slow. When it is unavailable, you have to decide in advance whether the answer is to let everything through or block everything, and both are bad in different ways. It is a reasonable architecture and it moves the risk rather than removing it, which is worth knowing before it is the thing that is down.
More on Zero trust
- Zero trust removes implicit trust in network position, not confidence in colleaguesIt was never about the people
- Continuous evaluation means decisions can changeYes is not for ever
- Policy enforcement depends on reliable identity signalsRight rule, smudged label
- Zero trust does not remove network controlsKeep the fence
- Service-to-service traffic needs identity tooMachines need names too
- Device trust should match what is actually measuredOnly what the probe touched
