{"id":93942,"date":"2021-06-30T06:00:43","date_gmt":"2021-06-30T13:00:43","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=93942"},"modified":"2023-05-15T23:10:30","modified_gmt":"2023-05-16T06:10:30","slug":"the-critical-role-of-zero-trust-in-securing-our-world","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/06\/30\/the-critical-role-of-zero-trust-in-securing-our-world\/","title":{"rendered":"The critical role of Zero Trust in securing our world"},"content":{"rendered":"
We are operating in the most complex cybersecurity landscape that we\u2019ve ever seen. While our current ability to detect and respond to attacks has matured incredibly quickly in recent years, bad actors haven\u2019t been standing still. Large-scale attacks like those pursued by Nobelium1<\/sup>\u00a0and Hafnium, alongside ransomware attacks on critical infrastructure indicate that attackers have become increasingly sophisticated and coordinated. It is abundantly clear that the work of cybersecurity and IT departments are critical to our national and global security.<\/p>\n Microsoft has a unique level of access to data on cyber threats and attacks globally, and we are committed to sharing this information and insights for the greater good.\u00a0As illustrated by recent attacks, we collaborate across the public and private sectors, as well as with our industry peers and partners,\u00a0to create a stronger, more intelligent\u00a0cybersecurity community for the protection of all.<\/p>\n This collaborative relationship includes the United States government, and we celebrate the fast-approaching milestones of the US Cybersecurity Executive Order2<\/sup> (EO). The EO specifies concrete actions to strengthen national cybersecurity and address increasingly sophisticated threats across federal agencies and the entire digital ecosystem. This order directs agencies and their suppliers to improve capabilities and coordination on information sharing, incident detection, incident response, software supply chain security, and IT modernization, which we support wholeheartedly.<\/p>\n With these national actions set in motion and a call for all businesses to enhance cybersecurity postures, Microsoft and our extensive partner ecosystem stand ready to help protect our world. The modern framework for protecting critical infrastructure, minimizing future incidents, and creating a safer world already exists: Zero Trust<\/a>. We have helped many public and private organizations to establish and implement a Zero Trust approach, especially in the wake of the remote and hybrid work tidal wave of 2020-2021. And Microsoft remains committed to delivering comprehensive, integrated security solutions at scale and supporting customers on every step of their security journey, including detailed guidance for Zero Trust deployment<\/a>.<\/p>\n The evidence is clear\u2014the old security paradigm of building an impenetrable fortress around your resources and data is simply not viable against today\u2019s challenges. Remote and hybrid work realities mean people move fluidly between work and personal lives, across multiple devices, and with increased collaboration both inside and outside of organizational boundaries. Entry points for attacks\u2014identities, devices, apps, networks, infrastructure, and data\u2014live outside the protections of traditional perimeters. The modern digital estate is distributed, diverse, and complex.<\/p>\n This new reality\u00a0requires\u00a0a Zero Trust approach.<\/p>\n Section 3<\/a> of the EO calls for \u201cdecisive steps\u201d for the federal government \u201cto modernize its approach to cybersecurity\u201d by accelerating the move to secure cloud services and Zero Trust implementation, including a mandate of multifactor authentication and end-to-end encryption of data. We applaud this recognition of the Zero Trust strategy as a cybersecurity best practice, as well as the White House encouragement of the private sector to take \u201cambitious measures\u201d in the same direction as the EO guidelines.<\/p>\n Per Section 3, federal standards and guidance for Zero Trust are developed by the National Institute of Standards and Technology<\/a> (NIST) of the US Department of Commerce, similar to other industry and scientific innovation measurements. NIST has defined Zero Trust in terms of several basic tenets<\/a>:<\/p>\n At Microsoft, we\u00a0have distilled\u00a0these\u00a0Zero Trust\u00a0tenets\u00a0into three\u00a0principles:\u00a0verify explicitly, use least privileged access, and assume breach.\u00a0We use these principles\u00a0for\u00a0our strategic guidance to customers,\u00a0software development, and global security\u00a0posture.<\/p>\n <\/p>\n Organizations that operate with a Zero Trust mentality are more resilient, consistent, and responsive to new attacks. A true end-to-end Zero Trust strategy not only makes it harder for attackers to get into the network but also minimizes potential blast radius by preventing lateral movement.<\/p>\n While preventing bad actors from gaining access is critical, it\u2019s only part of the Zero Trust equation. Being able to detect a sophisticated actor inside your environment is key to minimizing the impact of a breach. Sophisticated threat intelligence and analytics are critical for a rapid assessment of an attacker\u2019s behavior, eviction, and remediation.<\/p>\n We believe President Biden\u2019s EO is a timely call-to-action, not only for government agencies but as a model for all businesses looking to become resilient in the face of cyber threats. The heightened focus on incident response, data handling, collaboration, and implementation of Zero Trust should be a call-to-action for every organization\u2014public and private\u2014in the mission to better secure our global supply chain, infrastructure resources, information, and progress towards a better future.<\/p>\n Microsoft is committed to supporting federal agencies in answering the nation\u2019s call to strengthen inter- and intra-agency capabilities unlocking the government\u2019s full cyber capabilities. Recommended next steps for federal agencies<\/a> have been outlined by my colleague Jason Payne, Chief Technology Officer of Microsoft Federal. As part of this responsibility, we have provided Federal agencies with key Zero Trust Scenario Architectures<\/a> mapped to NIST standards, as well as a Zero Trust Rapid Modernization Plan<\/a>.<\/p>\n Microsoft is also committed to supporting customers in staying up to date with the latest security trends and developing the next generation of security professionals.\u202fWe have developed a set of skilling resources<\/a>\u202fto train teams on the capabilities identified in the EO and be ready to build a more secure, agile environment that supports every mission.<\/p>\n In addition to EO resources for federal government agencies, we are continuing to publish guidance, share learnings, develop resources, and invest in new capabilities to help organizations accelerate their Zero Trust adoption and meet their cybersecurity requirements.<\/p>\n The EO is an opportunity for all organizations to improve cybersecurity postures and act rapidly to implement Zero Trust, including multifactor authentication and end-to-end encryption. The White House has provided clear direction on what is required, and the Zero Trust framework can also be used as a model for private sector businesses, state and local governments, and organizations around the world.<\/p>\n We can only win as a team against these malicious attackers and significant challenges. Every step your organization takes in advancing a Zero Trust architecture not only secures your assets but also contributes to a safer world for all. We applaud organizations of every size for embracing Zero Trust, and we stand committed to partnering with you all on this journey.<\/p>\n To learn more about Microsoft Security solutions,\u00a0visit our\u00a0website<\/a>. Bookmark the\u00a0Security blog<\/a>\u00a0to keep up with our expert coverage on security matters. Also, follow us at\u00a0@MSFTSecurity<\/a>\u00a0for the latest news and updates on cybersecurity.<\/p>\n 1<\/sup>Nobelium Resource Center<\/a>, Microsoft Security Response Center. 04 March 2021.<\/p>\nZero Trust\u2019s critical role in\u00a0helping secure\u00a0our world<\/h2>\n
\n
Resources\u00a0for\u00a0strengthening national security\u00a0in the public and private sectors<\/h2>\n
Here are our top recommended\u00a0Zero Trust\u00a0resources:<\/h2>\n
\n
Tackling\u00a0sophisticated\u00a0cyber\u00a0threats\u00a0together<\/h2>\n
\n