错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Zero Trust and Compliance with Industry Frameworks and Regulations

  • Yuri Bobbert,
  • Tim Timmermans

摘要

In 2021, the United States president released an Executive Order directing the implementation of Zero Trust to protect federal institutes from cyber incidents. Organisations, not limited to government agencies, find it challenging to translate Zero Trust from strategy to operational implementation. At the same time, regulatory and industry requirements on cybersecurity skyrocketed. This paper deals with this dual complexity of both implementing Zero Trust and, at the same time, ensuring compliance with regulatory standards and frameworks. We start this paper by presenting the challenging situation of organisations in the current cyber threat landscape when facing increasingly stringent regulatory requirements. Next, we will introduce the core principles of Zero Trust, followed by the five-step model for Zero Trust implementation, including security measures, presented as an architectural repository. We explain how an exhaustive mapping of the Zero Trust-based repository measures to all major current frameworks and standards supports compliance with regulatory and industry frameworks. This paper provides a structured approach for implementing Zero Trust-related directives. At the same time, it offers guidance for aligning strategic, tactical and operational Zero Trust roadmaps with global or national regulations and industry compliance demands.