존 킨더백과 마이클 파넘이 파헤친 제로 트러스트에 대한 5가지 오해
In 2010, John Kindervag published No More Chewy Centers: Introducing The Zero Trust Model Of Information Security, a report detailing the new concept of Zero Trust he had created.
이 개념을 도입한 지 거의 15년 만에 사이버 보안 업계에서 널리 채택되었습니다. 그러나 시간이 지남에 따라 그 정의도 잘못 이해되고 있습니다. 사이버 복원력을 위해 노력하는 조직을 잘못된 길로 이끄는 몇 가지 제로 트러스트 속설이 등장했습니다.
현재 일루미오의 수석 에반젤리스트인 킨더백은 기록을 바로잡을 준비가 되어 있습니다. 그래서 그는 Trace3의 자문 CISO인 마이클 파넘과 함께 업계에서 가장 흔히 볼 수 있는 제로 트러스트에 대한 오해와 그 이면에 숨겨진 진실에 대해 이야기를 나눴습니다.
Watch their full discussion on demand, and keep reading to get the truth from the creator of Zero Trust and a leading security expert.
존 킨더백의 제로 트러스트에 대한 정의
The unique title of Kindervag’s report, No More Chewy Centers, comes from what he says is an old saying in information security: “We want our network to be like an M&M, with a hard crunchy outside and a soft chewy center.” The motto is based on the traditional Trust model of cybersecurity. It assumes attackers can’t get past the “hard crunchy outside” of the secured network perimeter.
하지만 킨더백은 "오늘날의 새로운 위협 환경에서 이러한 방식은 더 이상 효과적인 보안 강화 방법이 아닙니다."라고 설명합니다. 공격자가 셸을 통과하면 네트워크의 모든 리소스에 액세스할 수 있습니다."
The Zero Trust model is Kindervag’s response to this old security model.
"제로 트러스트는 전략입니다. 제품이 아닙니다. 당신은 그것을 살 수 없습니다."라고 그는 말했습니다.
제로 트러스트는 두 가지 기능을 수행하도록 설계되었습니다:
- Stop data breaches (Kindervag defines data breaches as incidents when sensitive or regulated data has been exfiltrated from a network or system into the hands of a malicious actor)
- 사이버 공격의 성공 차단
Zero Trust provides a roadmap for getting those two things done at a strategic level. It helps guide you to the right tactics and technologies.
"사이버 보안은 목적지가 아니라 여정입니다. 제로 트러스트도 마찬가지라고 생각합니다."라고 그는 언급했습니다.
킨더백의 제로 트러스트를 위한 5단계
- Define your protect surface: You can't control the attack surface because it's always evolving, but you can shrink your organization's protect surface into small, easily known parts. The protect surface usually includes a single data element, service, or asset.
- Map communication and traffic flows: You can't protect the system without understanding how it works. Getting visibility into your environments shows where controls are needed.
- Build the Zero Trust environment: Once you get complete visibility into the network, you can start implementing controls that are tailor-made for each protect surface.
- Create Zero Trust security policies: Build policies that provide granular rules allowing only permissible traffic to access the resource in the protect surface.
- Monitor and maintain the network: Inject telemetry back into the network, building a feedback loop that continuously improves security and builds a resilient, anti-fragile system.
제로 트러스트에 대한 오해 #1: 사이버 보안과 제로 트러스트에 대한 표준이 정해져 있습니다.
킨더백은 "전 세계에 사이버 보안 표준은 없습니다."라고 말합니다. 제로 트러스트에 대한 보고서를 발표했음에도 불구하고 NIST 및 CISA와 같은 기관은 사이버 보안 표준을 설정하지 않고 지침만 제공합니다.
“If you read CISA’s Zero Trust Maturity Model (ZTMM), they say it’s one way you might choose to do it. They’re not being prescriptive at all, and neither am I,” he explained.
이는 제로 트러스트에 대한 표준이 없다는 것을 의미하기도 합니다. 모든 조직은 고유한 특성을 가지고 있으며 제로 트러스트를 구축하는 데 고유한 접근 방식을 취해야 합니다. 보안 지침은 매우 유용할 수 있지만 반드시 최선의 방법은 아닙니다.

제로 트러스트에 대한 오해 #2: 체크리스트를 따르면 제로 트러스트를 사용할 수 있습니다.
사실 모든 조직의 제로 트러스트 여정은 각기 다를 것입니다. 규모, 성장, 예산, 리소스에 따라 다릅니다.
"성숙도 모델에서 어느 지점에 집중하고 싶은지, 그리고 그 지점에 도달하기 위해 무엇을 해야 하는지를 파악하는 것이 중요합니다."라고 Kindervag는 설명합니다.
Kindervag는 조직의 보호 표면부터 시작할 것을 권장합니다. 팀은 무엇을 보호해야 할까요? 이는 가장 중요한 자산을 보호하기 위해 선제적으로 준비하는 것이 아니라 위협에 대응하는 끝없는 무익한 사이클을 시작할 수 있는 공격 표면에서 시작하는 접근 방식과는 다릅니다.
파넘은 Trace3가 공격 표면에 집중하여 제로 트러스트 여정을 시작한 조직을 종종 보지만 함정에 빠졌다는 데 동의했습니다. 대신 Trace3는 고객이 먼저 보호 표면을 식별하여 Kindervag의 제로 트러스트를 위한 5가지 단계를 사용하도록 권장합니다.
제로 트러스트 오해 #3: 제로 트러스트는 ID 보안에 불과하다
킨더백은 제로 트러스트에 대해 "너무 문자 그대로" 접근하는 것을 경계했습니다. 많은 보안 리더에게 이는 성숙도 모델을 너무 엄격하게 따르는 것처럼 보일 수 있습니다.
킨더백은 "사람들은 제로 트러스트의 첫 번째 기둥이기 때문에 모든 신원 확인을 먼저 해야 한다고 생각합니다."라고 말합니다. 대신, 그는 조직이 고유한 보호 표면을 살펴보고 가장 중요한 리소스를 보호하는 제로 트러스트 기둥에 먼저 집중할 것을 권장합니다.
"세로로만 볼 것이 아니라 가로로 봐야 합니다."라고 킨더백은 설명합니다.
This often means organizations should focus on segmentation rather than identity. 13 years ago in his second report ever written on Zero Trust, Build Security Into Your Network’s DNA: The Zero Trust Network Architecture, Kindervag puts segmentation at the core of Zero Trust. As he says in the report, "New ways of segmenting networks must be created because all future networks need to be segmented by default."
Segmentation, also called Zero Trust Segmentation, is an essential part of Zero Trust. You can't achieve Zero Trust with out.

제로 트러스트 오해 #4: 제로 트러스트 플랫폼을 구매하면 제로 트러스트 보안을 사용할 수 있습니다.
사이버 보안 업계에 종사하는 분이라면 방어라는 용어를 많이 들어보셨을 겁니다. 하지만 많은 조직에서 이 개념은 '깊이 있는 비용'으로 바뀌었다고 Kindervag는 말합니다.
보안 솔루션에 그 어느 때보다 많은 비용을 지출하고 있는데도 여전히 심각한 사이버 사고가 발생하는 이유는 무엇일까요?
킨더백은 "보안이 충분한 물건을 사거나 충분한 돈을 쓰는 것이라면, 우리는 충분히 해냈습니다."라고 말합니다.
파넘은 많은 기업이 보호해야 할 대상을 먼저 이해하지 못한 채 보안 플랫폼에 비용을 지출하는 것을 본다고 말했습니다. Trace3는 고객이 더 이상 구매하기 전에 제로 트러스트에 대한 생각을 전환할 것을 권장합니다. 네트워크에 대한 가시성을 확보하고 보안에 가장 중요한 것이 무엇인지 파악하는 데 집중합니다.
Kindervag는 이 접근 방식을 지지했습니다. "우리는 마법처럼 자동으로 작동하는 마법 같은 기능을 원합니다. 하지만 그런 식으로 작동하는 것은 아닙니다. 항상 보호 표면부터 시작해야 합니다."
제로 트러스트 오해 #5: '제로 트러스트'는 오래된 보안 개념을 새롭게 포장한 것일 뿐입니다.
사이버 보안 업계의 일부에서는 제로 트러스트의 유효성에 의문을 제기하기도 합니다. 그들은 이를 오래된 아이디어를 새롭게 포장한 마케팅 전문용어라고 비난했습니다.
하지만 킨더백의 경우, 이는 그들이 개념을 잘못 이해하고 있다는 것을 보여줄 뿐입니다. "제로 트러스트 이전의 제로 트러스트는 무엇이었나요? 제로 트러스트는 존재하지 않았습니다. 그게 문제였습니다."라고 그는 말했습니다.
In the 20th century, the focus was on perimeter-based security. Networks were designed from the outside in: the outside was untrusted and the inside was trusted. This created completely wide-open flat networks on the inside. With this design, attackers can not only get inside the network, but they can stay there for days, week, months, even years.
"사고방식을 재설정해야 합니다." 파넘이 동의했습니다. "모든 인터페이스는 신뢰할 수 없는 것이어야 합니다. 네트워크가 가동되고 있다고 해서 안전하다는 의미는 아닙니다."
제로 트러스트 전략을 발전시키기 위한 Illumio + Trace3 파트너십

Trace3 is a leading technology consulting firm helping clients build, innovate, and manage their entire IT sphere, including cybersecurity. They’ve partnered with Illumio to help clients build Zero Trust security with Zero Trust Segmentation.
이 파트너십은 제로 트러스트 아키텍처를 구축하고 구현하기 위한 포괄적인 접근 방식을 제공합니다. Trace3의 전략적 전문성과 Illumio의 고급 세분화 기술을 결합하면 조직의 보안 요구 사항에 맞는 제로 트러스트에 대한 맞춤형 접근 방식을 찾을 수 있습니다.
Watch Kindervag’s and Farnum’s full conversation on demand. Contact us today to learn how Illumio + Trace3 can help your organization build Zero Trust.





