The US Office of Management and Budget (OMB) this week released a strategy memorandum directing Federal agencies to move closer to zero trust architecture. The memorandum follows up on US President Joe Biden’s Executive Order on cyber security (EO 14028) released in May 2021, which included an important section on implementing zero trust architecture.
“The foundational tenet of the Zero Trust Model is that no actor, system, network, or service operating outside or within the security perimeter is trusted. Instead, we must verify anything and everything attempting to establish access. It is a dramatic paradigm shift in philosophy of how we secure our infrastructure, networks, and data, from verify once at the perimeter to continual verification of each user, device, application, and transaction.”
The memorandum highlights the need for stronger identity and access controls and directs agencies to "consolidate identity systems so that protections and monitoring can be consistently applied". It also calls on Federal agencies to welcome external partners and independent perspectives to evaluate the security of agency applications, and to develop initiatives and guidance on classifying data based on sensitivity, criticality and protection requirements.
Federal agencies are required to meet the goals laid out in the memorandum by the end of FY 2024. The goals are based on the Cybersecurity and Infrastructure Security Agency's (CISA's) five zero trust pillars - Identity, Devices, Networks, Application & Workloads, and Data.
Federal agencies have 60 days to build upon their existing zero trust implementation plans by incorporating the additional requirements included in the memorandum.
While the memorandum is addressed to US Federal agencies and departments, it is significant in the global cyber security context and will encourage and increase the pace of zero trust adoption by both government and private entities worldwide.
With cyberattacks on the rise in New Zealand, Australia, and the wider JAPAC region, businesses in the region will benefit immensely by adopting a zero trust approach to security. The model is especially effective at detecting and blocking threats that bypass traditional security controls and make it past the network perimeter.
With its team of skilled security engineers and analysts, and best-in-class endpoint and network protection technology, LinearStack is uniquely qualified to help organisations implement zero trust security principles across their environments. We are headquartered in Auckland, New Zealand, and manage the security infrastructure and operations of some of the largest organisations in the APAC region. Our team can assess your existing security architecture, identify the gaps and vulnerabilities in your environment, and design your security infrastructure based on zero trust security principles.
Call us at 0800 008 795 or email us at info@linearstack.co.nz to book a free two-hour consult with one of our experts.
To know more about zero trust principles and the steps needed to implement the model, read this blog post.