{"id":2455,"date":"2019-09-18T07:00:21","date_gmt":"2019-09-18T14:00:21","guid":{"rendered":"https:\/\/www.microsoft.com\/sk-sk\/2019\/09\/18\/why-banks-adopt-modern-cybersecurity-zero-trust-model\/"},"modified":"2022-06-28T11:24:12","modified_gmt":"2022-06-28T18:24:12","slug":"why-banks-adopt-modern-cybersecurity-zero-trust-model","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/sk-sk\/microsoft-365\/blog\/2019\/09\/18\/why-banks-adopt-modern-cybersecurity-zero-trust-model\/","title":{"rendered":"Pre\u010do si banky osvojuj\u00fa modern\u00fd pr\u00edstup ku kybernetickej bezpe\u010dnosti \u2013 model nulovej d\u00f4very"},"content":{"rendered":"
Mnoh\u00e9 banky sa pri ochrane pred \u0161kodliv\u00fdmi \u00fatokmi v\u00a0s\u00fa\u010dasnosti aj na\u010falej spoliehaj\u00fa na pr\u00edstup zabezpe\u010denia \u201en\u00e1razn\u00edkovej oblasti\u201c, ktor\u00fd sa d\u00e1 prirovna\u0165 k\u00a0hradu obohnan\u00e9mu priekopou. Rovnako ako stredovek\u00e9 hrady chr\u00e1nen\u00e9 kamenn\u00fdmi hradbami, priekopami a\u00a0br\u00e1nami, banky, ktor\u00e9 pou\u017e\u00edvaj\u00fa zabezpe\u010denie n\u00e1razn\u00edkovej oblasti, musia investova\u0165 ve\u013ek\u00e9 prostriedky do n\u00e1razn\u00edkov\u00fdch siet\u00ed ako br\u00e1ny firewall, servery proxy, honeypoty a\u00a0\u010fal\u0161ie n\u00e1stroje na ochranu pred prienikmi. Zabezpe\u010denie n\u00e1razn\u00edkovej oblasti chr\u00e1ni vstupn\u00e9 a\u00a0v\u00fdstupn\u00e9 body siete t\u00fdm, \u017ee overuje \u00fadajov\u00e9 pakety a\u00a0identitu pou\u017e\u00edvate\u013eov, ktor\u00ed vstupuj\u00fa do siete organiz\u00e1cie alebo ju op\u00fa\u0161\u0165aj\u00fa, a\u00a0potom predpoklad\u00e1, \u017ee aktivita vo vn\u00fatri oblasti so spr\u00edsnen\u00fdm zabezpe\u010den\u00edm je relat\u00edvne bezpe\u010dn\u00e1.<\/p>\n
Chytr\u00e9 finan\u010dn\u00e9 in\u0161tit\u00facie sa teraz od tejto paradigmy odkl\u00e1\u0148aj\u00fa a\u00a0za\u010d\u00ednaj\u00fa vyu\u017e\u00edva\u0165 modern\u00fd pr\u00edstup ku kybernetickej bezpe\u010dnosti \u2013 model nulovej d\u00f4very. \u00dastredn\u00fdm princ\u00edpom modelu Nulov\u00e1 d\u00f4vera (Zero Trust) je predvolene nikomu a\u00a0ni\u010domu ned\u00f4verova\u0165 (interne ani externe) a\u00a0pred udelen\u00edm pr\u00edstupu vy\u017eadova\u0165 pr\u00edsne overenie ka\u017edej osoby alebo ka\u017ed\u00e9ho zariadenia.<\/p>\n
M\u00fary hradu maj\u00fa aj na\u010falej d\u00f4le\u017eit\u00fa \u00falohu, ale namiesto \u010fal\u0161\u00edch a\u00a0\u010fal\u0161\u00edch invest\u00edci\u00ed do hrub\u0161\u00edch hradieb a\u00a0hlb\u0161\u00edch priekop prin\u00e1\u0161a model nulovej d\u00f4very zdokonalen\u00fd sp\u00f4sob riadenia pr\u00edstupu k\u00a0identit\u00e1m, \u00fadajom a\u00a0zariadeniam v\u00a0tomto hrade. Nez\u00e1le\u017e\u00ed teda na tom, \u010di intern\u00fd \u00fa\u010dastn\u00edk kon\u00e1 \u0161kodlivo alebo nedbanlivo, alebo \u010di sa tajomn\u00fdm \u00fato\u010dn\u00edkom podar\u00ed prerazi\u0165 hradby \u2013 automatick\u00fd pr\u00edstup k\u00a0\u00fadajom nie je povolen\u00fd.<\/p>\n
Pokia\u013e ide o\u00a0zabezpe\u010denie digit\u00e1lneho majetku dne\u0161n\u00fdch ve\u013ek\u00fdch podnikov, pr\u00edstup \u201ehradu a\u00a0priekopy\u201c m\u00e1 kritick\u00e9 obmedzenia, preto\u017ee kybernetick\u00e9 hrozby od z\u00e1kladov zmenili defin\u00edciu ochrany. Ve\u013ek\u00e9 organiz\u00e1cie vr\u00e1tane b\u00e1nk musia zvl\u00e1dnu\u0165 rozpt\u00fdlen\u00e9 siete \u00fadajov a\u00a0aplik\u00e1ci\u00ed, ku ktor\u00fdm z\u00edskavaj\u00fa pr\u00edstup zamestnanci, z\u00e1kazn\u00edci aj partneri, lok\u00e1lne aj online. V\u00a0d\u00f4sledku toho je obrana n\u00e1razn\u00edkovej oblasti hradu zlo\u017eitej\u0161ia. Dokonca aj v\u00a0pr\u00edpade, \u017ee priekopa poskytne ochranu pred \u00fato\u010dn\u00edkmi, proti zneu\u017eit\u00fdm identit\u00e1m alebo in\u00fdm intern\u00fdm hrozb\u00e1m, ktor\u00e9 \u010d\u00edhaj\u00fa za hradbami, toho ve\u013ea nezm\u00f4\u017ee.<\/p>\n
Pr\u00edpady uveden\u00e9 ni\u017e\u0161ie predstavuj\u00fa v\u0161etky mo\u017en\u00fd zdroj vystavenia riziku a\u00a0s\u00fa be\u017en\u00e9 v\u00a0bank\u00e1ch, ktor\u00e9 sa spoliehaj\u00fa na bezpe\u010dnostn\u00fd pr\u00edstup \u201ehradu a\u00a0priekopy\u201c:<\/p>\n
V\u00fdhody pr\u00edstupu Nulov\u00e1 d\u00f4vera (Zero Trust) s\u00fa dobre zdokumentovan\u00e9<\/a> a\u00a0narastaj\u00faci po\u010det pr\u00edkladov z\u00a0re\u00e1lneho sveta ukazuje, \u017ee tento pr\u00edstup mohol zabr\u00e1ni\u0165 sofistikovan\u00fdm kybernetick\u00fdm \u00fatokom. Mnoho b\u00e1nk v\u0161ak e\u0161te aj v\u00a0s\u00fa\u010dasnosti pou\u017e\u00edva postupy, ktor\u00e9 sa od princ\u00edpu Nulov\u00e1 d\u00f4vera (Zero Trust) l\u00ed\u0161ia.<\/p>\n Prijatie modelu nulovej d\u00f4very m\u00f4\u017ee bank\u00e1m pom\u00f4c\u0165 posilni\u0165 zabezpe\u010denie, aby dok\u00e1zali bez ob\u00e1v podporova\u0165 iniciat\u00edvy pon\u00fakaj\u00face zamestnancom a\u00a0z\u00e1kazn\u00edkom viac flexibility. Vedenie banky by povedzme mohlo umo\u017eni\u0165 v\u00e4\u010d\u0161iu slobodu pohybu zamestnancom, ktor\u00ed pracuj\u00fa so z\u00e1kazn\u00edkmi, napr\u00edklad mana\u017e\u00e9rom vz\u0165ahov a\u00a0finan\u010dn\u00fdm poradcom, aby nemuseli sedie\u0165 za stolom a\u00a0mohli sa s\u00a0klientmi stret\u00e1va\u0165 mimo banky. Mnoh\u00e9 finan\u010dn\u00e9 in\u0161tit\u00facie dnes podporuj\u00fa t\u00fato geografick\u00fa agilnos\u0165 pomocou anal\u00f3gov\u00fdch n\u00e1strojov, ako s\u00fa napr\u00edklad papierov\u00e9 v\u00fdtla\u010dky alebo statick\u00e9 zobrazenia od pr\u00e1vneho poradcu. Zamestnanci b\u00e1nk aj z\u00e1kazn\u00edci v\u0161ak o\u010dak\u00e1vaj\u00fa dynamickej\u0161\u00ed z\u00e1\u017eitok pri pou\u017e\u00edvan\u00ed re\u00e1lnych \u00fadajov.<\/p>\n Banky, ktor\u00e9 sa pri zabezpe\u010den\u00ed spoliehaj\u00fa na pr\u00edstup \u201ehradu a\u00a0priekopy\u201c, maj\u00fa obavy uvo\u013e\u0148ova\u0165 \u00fadaje mimo svoju fyzick\u00fa sie\u0165. Bank\u00e1ri a\u00a0finan\u010dn\u00ed poradcovia sa tak m\u00f4\u017eu oprie\u0165 o\u00a0dynamick\u00e9 modely osved\u010den\u00fdch a\u00a0kategorizovan\u00fdch investi\u010dn\u00fdch strat\u00e9gi\u00ed len vtedy, ke\u010f sa stretnutia s\u00a0klientmi konaj\u00fa priamo v\u00a0banke<\/em>.<\/p>\n Z\u00a0historick\u00e9ho h\u013eadiska bolo pre bank\u00e1rov alebo finan\u010dn\u00fdch poradcov \u0165a\u017ekop\u00e1dne zdie\u013ea\u0165 aktualiz\u00e1cie modelov v\u00a0re\u00e1lnom \u010dase alebo akt\u00edvne spolupracova\u0165 s\u00a0in\u00fdmi bank\u00e1rmi \u010di obchodn\u00edkmi, aspo\u0148 nie bez VPN siet\u00ed. T\u00e1to agilnos\u0165 je v\u0161ak d\u00f4le\u017eitou hnacou silou spr\u00e1vnych investi\u010dn\u00fdch rozhodnut\u00ed a\u00a0spokojnosti z\u00e1kazn\u00edkov. Model Nulov\u00e1 d\u00f4vera (Zero Trust) umo\u017e\u0148uje mana\u017e\u00e9rovi vz\u0165ahov alebo analytikovi vyu\u017e\u00edva\u0165 preh\u013eady od poskytovate\u013eov trhov\u00fdch \u00fadajov, vytv\u00e1ra\u0165 vlastn\u00e9 modely a\u00a0dynamicky pracova\u0165 na r\u00f4znych klientskych scen\u00e1roch kedyko\u013evek a\u00a0kdeko\u013evek.<\/p>\n Dobrou spr\u00e1vou je, \u017ee ide o\u00a0nov\u00fa \u00e9ru inteligentn\u00e9ho zabezpe\u010denia podporovan\u00e9ho cloudom a\u00a0architekt\u00farou Nulov\u00e1 d\u00f4vera (Zero Trust), ktor\u00e9 dok\u00e1\u017ee zjednodu\u0161i\u0165 a\u00a0modernizova\u0165 zabezpe\u010denie a\u00a0dodr\u017eiavanie s\u00faladu v\u00a0bank\u00e1ch.<\/p>\n So slu\u017ebou Microsoft 365<\/a> m\u00f4\u017eu banky prija\u0165 okam\u017eit\u00e9 kroky smerom k\u00a0zabezpe\u010deniu Nulov\u00e1 d\u00f4vera (Zero Trust) \u2013 t\u00fdm, \u017ee nasadia tri k\u013e\u00fa\u010dov\u00e9 strat\u00e9gie:<\/p>\n Banky tie\u017e m\u00f4\u017eu nasadi\u0165 siln\u00e9 met\u00f3dy overovania, ako napr\u00edklad dvojfaktorov\u00e9 overovanie alebo viacfaktorov\u00e9 overovanie (Multi-Factor Authentication, MFA)<\/a> bez potreby hesla, \u010do m\u00f4\u017ee zn\u00ed\u017ei\u0165 riziko naru\u0161enia a\u017e o\u00a099,9\u00a0%. Aplik\u00e1cia Microsoft Authenticator<\/a> podporuje push ozn\u00e1menia, jednorazov\u00e9 pr\u00edstupov\u00e9 k\u00f3dy a\u00a0biometriu pre \u013eubovo\u013en\u00fa aplik\u00e1ciu pripojen\u00fa k\u00a0slu\u017ebe Azure AD.<\/p>\n Pre zariadenia s\u00a0Windowsom m\u00f4\u017eu zamestnanci b\u00e1nk pou\u017e\u00edva\u0165 Windows Hello<\/a>, funkciu bezpe\u010dn\u00e9ho a\u00a0pohodln\u00e9ho rozpoznania tv\u00e1re pri prihlasovan\u00ed do zariaden\u00ed. Nakoniec m\u00f4\u017eu banky pou\u017e\u00edva\u0165 podmienen\u00fd pr\u00edstup v\u00a0Azure AD<\/a> na ochranu prostriedkov pred podozriv\u00fdmi po\u017eiadavkami \u2013 t\u00fdm, \u017ee pou\u017eij\u00fa pr\u00edslu\u0161n\u00e9 politiky pr\u00edstupu. Slu\u017eby Microsoft Intune a\u00a0Azure AD navz\u00e1jom spolupracuj\u00fa, aby ste mali istotu, \u017ee k\u00a0slu\u017eb\u00e1m Office 365 vr\u00e1tane e-mailov a\u00a0lok\u00e1lnych aplik\u00e1ci\u00ed<\/a> bud\u00fa ma\u0165 pr\u00edstup len spravovan\u00e9 a\u00a0kompatibiln\u00e9 zariadenia. Prostredn\u00edctvom slu\u017eby Intune m\u00f4\u017eete tie\u017e vyhodnoti\u0165 stav dodr\u017eiavania s\u00faladu v\u00a0zariadeniach. Politika podmienen\u00e9ho pr\u00edstupu sa vyn\u00fati na z\u00e1klade stavu dodr\u017eiavania s\u00faladu konkr\u00e9tneho zariadenia v\u00a0\u010dase, kedy sa pou\u017e\u00edvate\u013e pok\u00fasi z\u00edska\u0165 pr\u00edstup k\u00a0\u00fadajom.<\/p>\n <\/p>\n ilustr\u00e1cia podmienen\u00e9ho pr\u00edstupu.<\/em><\/p>\n <\/p>\n Centrum zabezpe\u010denia pre Microsoft 365.<\/em><\/p>\n <\/p>\n Pr\u00edklad scen\u00e1ra klasifik\u00e1cie a\u00a0ochrany.<\/em><\/p>\n Slu\u017eba Microsoft 365 pom\u00e1ha zjednodu\u0161i\u0165 spravovanie zabezpe\u010denia v\u00a0modernej architekt\u00fare nulovej d\u00f4very a\u00a0vyu\u017e\u00edva preh\u013eady, \u0161k\u00e1lovanie a\u00a0funkcie inteligencie potrebn\u00e9 na boj proti po\u010d\u00edta\u010dovej kriminalite.<\/p>\n Ke\u010f zva\u017eujete, ak\u00fdm sp\u00f4sobom chr\u00e1ni\u0165 svoj modern\u00fd \u201ehrad\u201c, prostredie Nulov\u00e1 d\u00f4vera (Zero Trust) je optim\u00e1lne pre modern\u00e9 hrozby kybernetickej bezpe\u010dnosti. Prostredie nulovej d\u00f4very vy\u017eaduje okam\u017eit\u00fd doh\u013ead nad t\u00fdm, kto m\u00e1 pr\u00edstup k\u00a0\u010domu, kde a\u00a0kedy \u2013 a\u00a0\u010di k\u00a0dan\u00e9mu prostriedku v\u00f4bec m\u00e1 ma\u0165 pr\u00edstup.<\/p>\n Funkcie zabezpe\u010denia a\u00a0dodr\u017eiavania s\u00faladu<\/a> v\u00a0slu\u017ebe Microsoft 365 pom\u00e1haj\u00fa organiz\u00e1ci\u00e1m overi\u0165 pou\u017e\u00edvate\u013ea alebo zariadenie predt\u00fdm, ako mu bud\u00fa d\u00f4verova\u0165. Microsoft 365 tie\u017e pon\u00faka komplexn\u00e9 rie\u0161enie na t\u00edmov\u00fa pr\u00e1cu a\u00a0podporu produktivity<\/a>. Microsoft 365 tak predstavuje komplexn\u00e9 rie\u0161enie, ktor\u00e9 pom\u00f4\u017ee vedeniu banky zamera\u0165 sa na z\u00e1kazn\u00edkov a\u00a0inov\u00e1cie.<\/p>\n","protected":false},"excerpt":{"rendered":" Mnoh\u00e9 banky sa pri ochrane pred \u0161kodliv\u00fdmi \u00fatokmi v\u00a0s\u00fa\u010dasnosti aj na\u010falej spoliehaj\u00fa na pr\u00edstup zabezpe\u010denia \u201en\u00e1razn\u00edkovej oblasti\u201c, ktor\u00fd sa d\u00e1 prirovna\u0165 k\u00a0hradu obohnan\u00e9mu priekopou. Rovnako ako stredovek\u00e9 hrady chr\u00e1nen\u00e9 kamenn\u00fdmi hradbami, priekopami a\u00a0br\u00e1nami, banky, ktor\u00e9 pou\u017e\u00edvaj\u00fa zabezpe\u010denie n\u00e1razn\u00edkovej oblasti, musia investova\u0165 ve\u013ek\u00e9 prostriedky do n\u00e1razn\u00edkov\u00fdch siet\u00ed ako br\u00e1ny firewall, servery proxy, honeypoty a\u00a0\u010fal\u0161ie n\u00e1stroje na<\/p>\n","protected":false},"author":0,"featured_media":2459,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ep_exclude_from_search":false,"_classifai_error":"","footnotes":""},"content-type":[149],"product":[151],"audience":[198,196],"tags":[222,259,228],"coauthors":[],"class_list":["post-2455","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","content-type-news","product-microsoft-365","audience-banking","audience-enterprise","tag-azure","tag-windows-hello","tag-zero-trust-security"],"yoast_head":"\nMicrosoft 365 pom\u00e1ha pri transform\u00e1cii zabezpe\u010denia b\u00e1nk<\/h3>\n
\n
\n
\n
Zjednodu\u0161enie spravovania zabezpe\u010denia s\u00a0modelom Nulov\u00e1 d\u00f4vera (Zero Trust)<\/h3>\n