/
Segmentation

ジョン・キンダーヴァグとマイケル・ファーナムによって打ち破られた5つのゼロトラスト神話

In 2010, John Kindervag published No More Chewy Centers: Introducing The Zero Trust Model Of Information Security, a report detailing the new concept of Zero Trust he had created.

彼がこの概念を導入してから約 15 年間で、サイバーセキュリティ業界で広く採用されています。しかし、その定義も時間の経過とともに誤解されてきました。サイバーレジリエンスに向けて取り組む組織を迷わせるゼロトラストの神話がいくつか浮かび上がっています。  

現在、イルミオのチーフエバンジェリストであるキンダーヴァグ氏は、事実を正す準備ができています。そのため、彼はTrace3のアドバイザリーCISOであるMichael Farnum氏とともに炉辺談話を行い、業界で見られる最も一般的なゼロトラスト神話とその背後にある真実について話し合いました。  

Watch their full discussion on demand, and keep reading to get the truth from the creator of Zero Trust and a leading security expert.

John Kindervagのゼロトラストの定義

The unique title of Kindervag’s report, No More Chewy Centers, comes from what he says is an old saying in information security: “We want our network to be like an M&M, with a hard crunchy outside and a soft chewy center.” The motto is based on the traditional Trust model of cybersecurity. It assumes attackers can’t get past the “hard crunchy outside” of the secured network perimeter.

しかし、Kindervagが説明するように、「今日の新しい脅威の状況では、これはもはやセキュリティを強化する効果的な方法ではありません。攻撃者がシェルを通過すると、ネットワーク内のすべてのリソースにアクセスできるようになります。」  

The Zero Trust model is Kindervag’s response to this old security model.

「ゼロトラストは戦略です。それは製品ではありません。買えない」と彼は語った。

ゼロトラストは、次の 2 つのことを行うように設計されています。

  • Stop data breaches (Kindervag defines data breaches as incidents when sensitive or regulated data has been exfiltrated from a network or system into the hands of a malicious actor)
  • サイバー攻撃の成功を阻止

Zero Trust provides a roadmap for getting those two things done at a strategic level. It helps guide you to the right tactics and technologies.  

「サイバーセキュリティは旅であり、目的地ではありません。ゼロトラストにも同じことが当てはまると思います」と彼は指摘した。  

Kindervagのゼロトラストへの5つのステップ
  1. Define your protect surface: You can't control the attack surface because it's always evolving, but you can shrink your organization's protect surface into small, easily known parts. The protect surface usually includes a single data element, service, or asset.
  1. Map communication and traffic flows: You can't protect the system without understanding how it works. Getting visibility into your environments shows where controls are needed.
  1. Build the Zero Trust environment: Once you get complete visibility into the network, you can start implementing controls that are tailor-made for each protect surface.
  1. Create Zero Trust security policies: Build policies that provide granular rules allowing only permissible traffic to access the resource in the protect surface.
  1. Monitor and maintain the network: Inject telemetry back into the network, building a feedback loop that continuously improves security and builds a resilient, anti-fragile system.

ゼロトラスト神話 #1: サイバーセキュリティとゼロトラストには定義された基準がある

「世界にはサイバーセキュリティ基準はありません」とキンダーヴァグ氏は語った。ゼロトラストに関するレポートが公開されているにもかかわらず、NISTやCISAなどの組織はサイバーセキュリティ基準を設定せず、ガイダンスを提供するだけです。

“If you read CISA’s Zero Trust Maturity Model (ZTMM), they say it’s one way you might choose to do it. They’re not being prescriptive at all, and neither am I,” he explained.  

これは、ゼロトラストの標準がないことも意味します。すべての組織はユニークであり、ゼロトラストを構築するために独自のアプローチを取る必要があります。セキュリティ ガイダンスは非常に役立ちますが、必ずしも最善の方法ではありません。

CISAゼロトラスト成熟度モデル(ZTMM)の5つの柱
CISAのゼロトラスト成熟度モデル(ZTMM)の5つの柱は、規範的な基準ではなく、ゼロトラストガイダンスです。

ゼロトラスト神話 #2: チェックリストに従うことでゼロトラストを取得できます

実際、すべての組織のゼロトラストへの取り組みは異なります。それは、規模、成長、予算、リソースによって異なります。  

「成熟度モデルのどこに焦点を当てたいのか、そしてそれに到達するために何をする必要があるのかを理解することが重要です」とキンダーヴァッグ氏は説明した。  

Kindervag では、組織の保護サーフェスから始めることをお勧めします。チームは、何を守る必要があるのかを問わなければなりません。これは、最も重要な資産を保護するための準備を積極的に行うのではなく、脅威に対応するという終わりのない無益なサイクルを開始する可能性がある攻撃対象領域から始まるアプローチとは異なります。

Farnum氏は、Trace3では、攻撃対象領域に焦点を当ててゼロトラストへの取り組みを開始した組織をよく見かけますが、落とし穴に遭遇していることに同意しました。代わりに、Trace3 は、最初に保護面を特定することで、Kindervag のゼロ トラストへの 5 つのステップを使用することをクライアントに奨励しています。

ゼロトラスト神話 #3: ゼロトラストは単なるアイデンティティセキュリティです  

Kindervag 氏は、ゼロトラストを「文字通り」にしすぎないように警告しました。多くのセキュリティリーダーにとって、これは成熟度モデルに厳密に従いすぎているように見えるかもしれません。

「人々は、アイデンティティのすべてを最初に行わなければならないと感じています。なぜなら、それがゼロトラストの最初の柱だからです」とキンダーヴァッグ氏は語った。代わりに、彼は組織に独自の保護面に目を向け、最も重要なリソースを保護するゼロトラストの柱に最初に焦点を当てることを奨励しています。

「垂直方向だけでなく、水平方向に見る必要があります」とキンダーヴァッグ氏は説明した。

This often means organizations should focus on segmentation rather than identity. 13 years ago in his second report ever written on Zero Trust, Build Security Into Your Network’s DNA: The Zero Trust Network Architecture, Kindervag puts segmentation at the core of Zero Trust. As he says in the report, "New ways of segmenting networks must be created because all future networks need to be segmented by default."

Segmentation, also called Zero Trust Segmentation, is an essential part of Zero Trust. You can't achieve Zero Trust with out.

__wf_reserved_inherit

ゼロトラスト神話 #4: ゼロトラストプラットフォームを購入すると、ゼロトラストセキュリティが確保されることを意味します

サイバーセキュリティ業界に携わっている人なら、防御という言葉を深く聞いたことがあるでしょう。しかし、多くの組織にとって、この概念は「詳細な費用」に変わっているとキンダーヴァッグ氏は言います。

セキュリティソリューションにこれまで以上に多くの費用を費やしているのに、なぜ組織は依然として深刻なサイバーインシデントに苦しんでいるのでしょうか?

「セキュリティが十分なものを購入したり、十分なお金を費やしたりすることであるなら、私たちはそれを実行しました」とキンダーヴァッグ氏は語った。  

ファーナム氏は、多くの企業が何を保護する必要があるのかを最初に理解せずにセキュリティプラットフォームに資金を費やしているのを見ていると述べた。Trace3 は、クライアントに、これ以上購入する前にゼロトラストについての考え方を変えることを奨励しています。彼らは、ネットワークを可視化し、セキュリティで最も重要なものを知ることに戻っています。

キンダーヴァグはこのアプローチを支持しました。「私たちは、魔法のような妖精の粉のように自動的に動作するようにしたいだけです。しかし、それは仕組みではありません。常にプロテクトサーフェスから始めます。」

ゼロトラスト神話 #5: 「ゼロトラスト」は、古いセキュリティ概念の新しいパッケージにすぎません

サイバーセキュリティ業界の一部は、ゼロトラストの有効性に疑問を呈しています。彼らはそれを、古いアイデアを新しく包んだマーケティング用語として非難しました。

しかし、キンダーヴァグにとって、これは彼らが概念を誤解していることを示しているだけです。「ゼロトラスト以前のゼロトラストとは何でしたか?ゼロトラストはありませんでした。それが問題だった」と彼は語った。

In the 20th century, the focus was on perimeter-based security. Networks were designed from the outside in: the outside was untrusted and the inside was trusted. This created completely wide-open flat networks on the inside. With this design, attackers can not only get inside the network, but they can stay there for days, week, months, even years.  

「考え方をリセットする必要があります」とファーナムも同意した。「すべてのインターフェースは信頼できないべきです。ネットワークが稼働しているからといって、それが安全であるとは限りません。」

イルミオ + Trace3 がゼロトラスト戦略を推進するパートナー

Trace2 ロゴ

Trace3 is a leading technology consulting firm helping clients build, innovate, and manage their entire IT sphere, including cybersecurity. They’ve partnered with Illumio to help clients build Zero Trust security with Zero Trust Segmentation.  

このパートナーシップは、ゼロトラストアーキテクチャの構築と実装のための包括的なアプローチを提供します。Trace3の戦略的専門知識とイルミオの高度なセグメンテーションテクノロジーを組み合わせることで、組織のセキュリティニーズに合ったゼロトラストへのカスタマイズされたアプローチを見つけることができます。

Watch Kindervag’s and Farnum’s full conversation on demand. Contact us today to learn how Illumio + Trace3 can help your organization build Zero Trust.

関連記事

今すぐIllumio Insightsを体験してください

AI を活用した可観測性が、脅威をより迅速に検出、理解、封じ込めるのにどのように役立つかをご覧ください。