As the title of this posting probably tells you, there are a LOT of acronyms out there talking about Access Control. To level set, here are a few translations:
Hackers are extremely creative. It’s not just phishing and knocking, hackers will try every crevice, every small hole, even things you would never think of as a way into your data center. The reason you need Zero-trust security is because you never know how they’re going to slip behind the scenes and gain access to what you thought was an innocent little system.
Over the last 20+ years, if you didn’t offer an open API as a software maker, you were not invited to sit at the cool kids table. The culture of interconnected software has rapidly fostered tech prosperity & business growth to the point that the API has become the new database. Just imagine the possibilities, if you will, of an API so data rich that I can expose a decade of personal information for millions of users...what could possibly go wrong?
Back in 2007 Apple launched the iPhone and created a whole new way of developing software: Apps. Before Apps most development relied on a full stack of a UI tied closely to code that pulled content from databases. You secured the entire stack, and the idea of separating your security concerns was not only unheard of, but pretty much impossible to achieve.
Ask most companies today about their application strategy and they’ll say, “We’ve got it covered, we’re moving to the cloud.” To which I ask, “What are you moving to the cloud?”
You may have seen my posting on East/West is the New North/South. The bottom line is that traditional API Gateway models simply don’t provide the level of security we need in modern microservice architecture. The problem is that only 20% of the traffic (that is the inbound traffic up until the gateway) is secure, everything inside the data center is “trusted.”
In computer technology we talk about security breaches and how to prevent them, but honestly, we have different kinds of breaches and different reasons to want to prevent them. Sure we hear the stats like “60% of small companies that suffer a cyber-attack are out of business within six months” but what is it about those attacks that cripple and destroy companies? And how can we create better security policies and implement those policies so we don't suffer attacks?
The Cloudentity stack is very powerful and very flexible, which means it's hard to tell the story from one person's point of view. This short (1:15) video gives a quick view from four different people's perspectives.
We talk about network traffic in two ways – North/South traffic is the traffic heading in and out of your network. East/West traffic is the traffic from one server to another inside your network. So why do we focus so much on North/South and almost forget about East/West?
As I mentioned in Identity and Security Starts at Home, the era of Zero Trust means we can’t trust traffic coming from inside the house. Internal systems can be compromised and if your internal security is just IP whitelisting or trusted certs, a “trusted app” can do a lot of damage by probing the internal network.
Authorization has come along way since setting bits in the file system. With the advancements in Machine learning, big data and behavioral profiling its time for authorization to take its next generational leap and move into a flexible risk based access control model that works in concert with legacy access control policies.