{"id":2422,"date":"2019-09-18T07:00:21","date_gmt":"2019-09-18T14:00:21","guid":{"rendered":"https:\/\/www.microsoft.com\/lv-lv\/2019\/09\/18\/why-banks-adopt-modern-cybersecurity-zero-trust-model\/"},"modified":"2022-06-28T11:15:03","modified_gmt":"2022-06-28T18:15:03","slug":"why-banks-adopt-modern-cybersecurity-zero-trust-model","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/lv-lv\/microsoft-365\/blog\/2019\/09\/18\/why-banks-adopt-modern-cybersecurity-zero-trust-model\/","title":{"rendered":"K\u0101p\u0113c bankas ievie\u0161 m\u016bsdien\u012bgu pieeju kiberdro\u0161\u012bbai \u2014 nulles uzticam\u012bbas modeli"},"content":{"rendered":"
Daudzas bankas \u0161odien joproj\u0101m pa\u013caujas uz “pils un gr\u0101vja” pieeju, kas tiek d\u0113v\u0113ta ar\u012b par “perimetra dro\u0161\u012bbu”, lai aizsarg\u0101tu datus pret \u013caunpr\u0101t\u012bgiem uzbrukumiem. T\u0101pat k\u0101 viduslaiku pilis, kas ir aizsarg\u0101tas ar akmens sien\u0101m, gr\u0101vjiem un v\u0101rtiem, bankas, kas izmanto perimetra dro\u0161\u012bbu, daudz iegulda, lai stiprin\u0101tu to t\u012bkla perimetrus ar ugunsm\u016briem, starpniekserveriem, ur\u0137uslazdiem un citiem ielau\u0161an\u0101s nov\u0113r\u0161anas r\u012bkiem. Perimetra dro\u0161\u012bba aizsarg\u0101 ieejas un izejas punktus t\u012bkl\u0101, verific\u0113jot to lietot\u0101ju datu paketes un identit\u0101ti, kas iek\u013c\u016bst un iziet no organiz\u0101cijas t\u012bkla, un p\u0113c tam pie\u0146em, ka aktivit\u0101te aizsarg\u0101taj\u0101 perimetr\u0101 ir relat\u012bvi dro\u0161a.<\/p>\n
Pieredz\u0113ju\u0161as finan\u0161u iest\u0101des tagad atsak\u0101s no \u0161\u012bs paradigmas un ievie\u0161 m\u016bsdien\u012bgu pieeju kiberdro\u0161\u012bbai \u2014 nulles uzticam\u012bbas modeli. Nulles uzticam\u012bbas mode\u013ca galvenais princips ir p\u0113c noklus\u0113juma neuztic\u0113ties nevienam \u2014 iek\u0161\u0113jam vai \u0101r\u0113jam lietot\u0101jam \u2014, un pirms piek\u013cuves pie\u0161\u0137ir\u0161anas oblig\u0101ti j\u0101veic katras personas vai ier\u012bces verifik\u0101cija.<\/p>\n
Pils perimetrs joproj\u0101m ir svar\u012bgs, bet, t\u0101 viet\u0101, lai vienk\u0101r\u0161i ieguld\u012btu liel\u0101kas invest\u012bcijas sp\u0113c\u012bg\u0101ku sienu un plat\u0101ku gr\u0101vju rad\u012b\u0161anai, nulles uzticam\u012bbas modelis pied\u0101v\u0101 nians\u0113tu pieeju identit\u0101\u0161u, datu un ier\u012b\u010du p\u0101rvald\u012bbai \u0161aj\u0101 nosac\u012btaj\u0101 pil\u012b. T\u0101tad, neatkar\u012bgi no t\u0101, vai k\u0101ds iek\u0161\u0113jais lietot\u0101js darbojas \u013caunpr\u0101t\u012bgi vai pavir\u0161i, vai ar\u012b mask\u0113ti uzbruc\u0113ji tiek p\u0101ri pils sien\u0101m, netiek pie\u0161\u0137irta autom\u0101tiska piek\u013cuve datiem.<\/p>\n
Attiec\u012bb\u0101 uz m\u016bsdien\u012bga uz\u0146\u0113muma digit\u0101lo l\u012bdzek\u013cu aizsardz\u012bbu, pils un gr\u0101vja pieejai ir kritiski svar\u012bgi ierobe\u017eojumi, jo kiberapdraud\u0113jumu att\u012bst\u012bba ir radik\u0101li main\u012bjusi situ\u0101ciju. Lielas organiz\u0101cijas, tostarp bankas, darbojas ar izkais\u012btiem datu t\u012bkliem un lietojumprogramm\u0101m, kam piek\u013c\u016bst darbinieki, klienti un partneri kl\u0101tien\u0113 vai tie\u0161saist\u0113. T\u0101d\u0113j\u0101di pils perimetru aizsardz\u012bba ir apgr\u016btin\u0101ta. Pat tad, ja gr\u0101vis efekt\u012bvi attur ienaidniekus, tas neko \u012bsti nepal\u012bdz lietot\u0101jiem, kuriem ir apdraud\u0113tas identit\u0101tes vai citi iek\u0161\u0113ji apdraud\u0113jumi, kas jau atrodas pils sien\u0101s.<\/p>\n
T\u0101l\u0101k nor\u0101d\u012bt\u0101s metodes rada ievainojam\u012bbas riskus, un t\u0101s ir izplat\u012btas bank\u0101s, kas izmanto pils un gr\u0101vja pieeju dro\u0161\u012bbai.<\/p>\n
Priek\u0161roc\u012bbas, ko sniedz nulles uzticam\u012bba, ir labi dokument\u0113tas<\/a>, un arvien pieaugo\u0161s re\u0101lu gad\u012bjumu skaits nor\u0101da, ka \u0161\u012b pieeja b\u016btu var\u0113jusi nov\u0113rst sare\u017e\u0123\u012btus kiberuzbrukumus. Tom\u0113r daudzas bankas joproj\u0101m piekopj praksi, kas novirz\u0101s no nulles uzticam\u012bbas principiem.<\/p>\n Nulles uzticam\u012bbas modelis bank\u0101m var pal\u012bdz\u0113t uzlabot dro\u0161\u012bbas situ\u0101ciju, lai t\u0101s var\u0113tu p\u0101rliecino\u0161i atbalst\u012bt iniciat\u012bvas, kas darbiniekiem un klientiem nodro\u0161ina liel\u0101ku elast\u012bbu. Piem\u0113ram, bankas vad\u012bt\u0101ji labpr\u0101t v\u0113l\u0113tos savus pirm\u0101s saskares darbiniekus, kuri str\u0101d\u0101 tie\u0161\u0101 saikn\u0113 ar klientiem (klientu apkalpo\u0161anas speci\u0101listus un finan\u0161u konsultantus), atbr\u012bvot no pien\u0101kuma s\u0113d\u0113t pie galda un \u013caut tikties ar klientiem ar\u012b \u0101rpus bankas telp\u0101m. \u0160odien daudzas finan\u0161u iest\u0101des atbalsta \u0161o iesp\u0113ju ar analogajiem r\u012bkiem, piem\u0113ram, pap\u012bra izdruk\u0101m vai statisku inform\u0101ciju no apspried\u0113m. Tom\u0113r banku darbinieki un klienti sagaida dinamisk\u0101ku pieredzi, izmantojot re\u0101llaika datus.<\/p>\n Bankas, kas pa\u013caujas uz pils un gr\u0101vja pieeju dro\u0161\u012bbai, nev\u0113las savus datus izlaist \u0101rpus fizisk\u0101 t\u012bkla. L\u012bdz ar to ba\u0146\u0137ieri un finan\u0161u konsultanti var izmantot p\u0101rbaud\u012btus un strikti regul\u0113tus invest\u012bciju strat\u0113\u0123iju mode\u013cus, ja tik\u0161an\u0101s ar klientiem notiek bankas telp\u0101s<\/em>.<\/p>\n V\u0113sturiski ba\u0146\u0137ieriem vai finan\u0161u konsultantiem, atrodoties ce\u013c\u0101, ir bijis sare\u017e\u0123\u012bti kop\u012bgot re\u0101llaika mode\u013cu atjaunin\u0101jumus vai akt\u012bvi sadarbotos ar citiem ba\u0146\u0137ieriem vai tirgot\u0101jiem, vismaz ne bez VPN izmanto\u0161anas. Tom\u0113r \u0161\u012b elast\u012bba ir svar\u012bgs sapr\u0101t\u012bgu invest\u012bciju l\u0113mumu un klientu apmierin\u0101t\u012bbas veicin\u0101t\u0101js. Nulles uzticam\u012bbas modelis \u013cauj klientu rel\u0101ciju vad\u012bt\u0101jam vai anal\u012bti\u0137im izmantot inform\u0101ciju no tirgus datu sniedz\u0113jiem, sintez\u0113t ar saviem mode\u013ciem un dinamiski str\u0101d\u0101t ar da\u017e\u0101diem klientu scen\u0101rijiem jebkur\u0101 laik\u0101 un viet\u0101.<\/p>\n Lab\u0101 zi\u0146a ir t\u0101, ka \u0161\u012b ir jauna intelektiskas dro\u0161\u012bbas \u0113ra, ko nodro\u0161ina m\u0101ko\u0146a un nulles uzticam\u012bbas arhitekt\u016bra, kas var racionaliz\u0113t un moderniz\u0113t banku dro\u0161\u012bbu un atbilst\u012bbu.<\/p>\n Izmantojot Microsoft\u00a0365<\/a>, bankas var veikt t\u016bl\u012bt\u0113jus so\u013cus, lai ieviestu nulles uzticam\u012bbas dro\u0161\u012bbu, izvietojot tr\u012bs galven\u0101s strat\u0113\u0123ijas:<\/p>\n Bankas var ar\u012b izvietot stipras autentifik\u0101cijas metodes, piem\u0113ram, divu faktoru vai daudzfaktoru autentifik\u0101ciju (MFA)<\/a> bez paroles, kas var samazin\u0101t iebrukuma risku par 99,9 procentiem. Microsoft Authenticator<\/a> nodro\u0161ina pa\u0161pieg\u0101des pazi\u0146ojumus, vienreiz\u0113jus ieejas kodus un biometrisko inform\u0101ciju jebkur\u0101 ar Azure AD savienot\u0101 lietojumprogramm\u0101.<\/p>\n Windows ier\u012bc\u0113m banku darbinieki var izmantot Windows Hello<\/a>, dro\u0161u un \u0113rtu sejas atpaz\u012b\u0161anas l\u012bdzekli, lai pierakst\u012btos ier\u012bc\u0113s. Visbeidzot bankas var izmantot Azure Active Directory nosac\u012bto piek\u013cuvi<\/a>, lai aizsarg\u0101tu resursus no aizdom\u012bgiem piepras\u012bjumiem, ievie\u0161ot piem\u0113rotas piek\u013cuves politikas. Microsoft Intune un Azure Active Directory sadarbojas, lai nodro\u0161in\u0101tu, ka tikai p\u0101rvald\u012bt\u0101s un atbilst\u012bg\u0101s ier\u012bces var piek\u013c\u016bt Office\u00a0365 pakalpojumiem, tostarp e-pastam un lok\u0101laj\u0101m lietojumprogramm\u0101m<\/a>. Izmantojot Intune, varat ar\u012b nov\u0113rt\u0113t ier\u012b\u010du atbilst\u012bbas statusu. Nosac\u012bt\u0101s piek\u013cuves politika tiek ieviesta atkar\u012bb\u0101 no ier\u012bces atbilst\u012bbas statusa laik\u0101, kad lietot\u0101js m\u0113\u0123ina piek\u013c\u016bt datiem.<\/p>\n <\/p>\n Nosac\u012bt\u0101s piek\u013cuves att\u0113ls.<\/em><\/p>\n <\/p>\n Microsoft\u00a0365 dro\u0161\u012bbas centrs.<\/em><\/p>\n <\/p>\n Klasifik\u0101cijas un aizsardz\u012bbas scen\u0101rija piem\u0113rs.<\/em><\/p>\n Microsoft\u00a0365 pal\u012bdz vienk\u0101r\u0161ot dro\u0161\u012bbas p\u0101rvald\u012bbu m\u016bsdien\u012bg\u0101 absol\u016bt\u0101 uzticam\u012bbas arhitekt\u016br\u0101, nodro\u0161inot p\u0101rredzam\u012bbas, m\u0113rogo\u0161anas un inform\u0101cijas ieg\u016b\u0161anas iesp\u0113jas, kas nepiecie\u0161amas, lai c\u012bn\u012btos pret kibernoziegumiem.<\/p>\n Kam\u0113r apsverat, k\u0101 aizsarg\u0101t savu m\u016bsdienu “pili”, nulles uzticam\u012bbas vide ir optim\u0101l\u0101k\u0101 aizsardz\u012bba pret m\u016bsdienu kiberdro\u0161\u012bbas apdraud\u0113jumiem. Nulles uzticam\u012bbas vide nodro\u0161ina nep\u0101rtrauktu uzraudz\u012bbu par aktu\u0101lo piek\u013cuvi \u2014 tiek p\u0101rraudz\u012bti lietot\u0101ji, laiks, vieta un p\u0101rbaud\u012bts, vai vi\u0146iem ir piek\u013cuves ties\u012bbas.<\/p>\n Microsoft\u00a0365 dro\u0161\u012bbas un atbilst\u012bbas iesp\u0113jas<\/a> pal\u012bdz organiz\u0101cij\u0101m veikt verifik\u0101ciju, pirms uztic\u0113ties lietot\u0101jam vai ier\u012bcei. Microsoft\u00a0365 pied\u0101v\u0101 ar\u012b piln\u012bgu grupas darba un produktivit\u0101tes risin\u0101jumu<\/a>. Kopum\u0101 Microsoft\u00a0365 nodro\u0161ina visaptvero\u0161u risin\u0101jumu, lai pal\u012bdz\u0113tu banku vad\u012bt\u0101jiem koncentr\u0113ties uz klientiem un inov\u0101cij\u0101m.<\/p>\n","protected":false},"excerpt":{"rendered":" Daudzas bankas \u0161odien joproj\u0101m pa\u013caujas uz “pils un gr\u0101vja” pieeju, kas tiek d\u0113v\u0113ta ar\u012b par “perimetra dro\u0161\u012bbu”, lai aizsarg\u0101tu datus pret \u013caunpr\u0101t\u012bgiem uzbrukumiem. T\u0101pat k\u0101 viduslaiku pilis, kas ir aizsarg\u0101tas ar akmens sien\u0101m, gr\u0101vjiem un v\u0101rtiem, bankas, kas izmanto perimetra dro\u0161\u012bbu, daudz iegulda, lai stiprin\u0101tu to t\u012bkla perimetrus ar ugunsm\u016briem, starpniekserveriem, ur\u0137uslazdiem un citiem ielau\u0161an\u0101s<\/p>\n","protected":false},"author":0,"featured_media":2426,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ep_exclude_from_search":false,"_classifai_error":"","footnotes":""},"content-type":[146],"product":[148],"audience":[195,193],"tags":[219,256,225],"coauthors":[],"class_list":["post-2422","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","content-type-news","product-microsoft-365","audience-banking","audience-enterprise","tag-azure","tag-windows-hello","tag-zero-trust-security"],"yoast_head":"\nMicrosoft\u00a0365 pal\u012bdz transform\u0113t banku dro\u0161\u012bbu<\/h3>\n
\n
\n
\n
Vienk\u0101r\u0161ota dro\u0161\u012bbas p\u0101rvald\u012bba ar nulles uzticam\u012bbu<\/h3>\n