White Paper | A Holistic Approach to Zero Trust

White Paper | A Holistic Approach to Zero Trust

This white paper explores how organizations can implement a framework-agnostic Zero Trust model that secures enterprise resources across any location. Learn how to build, monitor, and optimize your security posture using the Identify, Detect, Protect, Respond, and Recover framework. Download the white paper to strengthen your Zero Trust strategy.

White Paper | A Holistic Approach to Zero Trust

©November 2023 Check Point Software Technologies Ltd. All rights reserved

Your ultimate journey to the Zero Trust security model

YOU DESERVE THE BEST SECURITY

Zero Trust operation framework

2

©November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK

ABSTRACT Organizations need to take a holistic approach to their Zero Trust strategic and tactical security needs. This includes using a framework-agnostic model that will ensure all enterprise resources are being accessed securely, regardless of their location1. Such can be achieved through the implementation of a security posture, monitoring the posture, and adjusting the posture through the Identify, Detect, Protect, Respond, and Recover methods. In the end, the enterprise assets and data will be protected in a virtue cycle.

AUDIENCE

The target audience of this document includes those involved in the management and operational functions of risk, information security, and information technology. This audience consists of the CISO, CIO, CTO, and those leading digital transformation initiatives where Zero Trust methods can help protect an organization’s data assets. As a prerequisite, you should be well-versed in enterprise architecture design concepts and generic security architectural concepts and frameworks.

1 The Gartner IT Security Approach for the Digital Age - URL: The Gartner It Security Approach For The Digital Age

https://www.gartner.com/smarterwithgartner/the-gartner-it-security-approach-for-the-digital-age

©November 2023 Check Point Software Technologies Ltd. All rights reserved

TABLE OF CONTENTS

INTRODUCTION ................................................................................................................................................... 2

WHAT IS THE ZERO TRUST FRAMEWORK? .......................................................................................................... 2

ZERO TRUST MATURITY MODEL AND IMPLEMENTATION .................................................................................. 9

TRANSFORMING ZERO TRUST WITH INFINITY GLOBAL SERVICES ..................................................................... 16

ZERO TRUST REFERENCE ARCHITECTURE .......................................................................................................... 20

ZERO TRUST ARCHITECTURE PILLARS ................................................................................................................ 23

ZERO TRUST OPERATIONAL MODEL .................................................................................................................. 28

ZERO TRUST AND CLOUD TRANSFORMATION .................................................................................................. 32

ZERO TRUST AND CYBER SECURITY MESH......................................................................................................... 37

CONCLUSION ..................................................................................................................................................... 40

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 2

Introduction In today's digital age, cyber threats loom large, and data breaches can have catastrophic consequences for businesses. Thus, it is imperative to have a robust cybersecurity posture; securing enterprise systems is challenging due to IT infrastructure, cloud environments, and changing applications. Traditional security focused on perimeters and endpoints, leaving internal networks and corporate users vulnerable, and the rise of cloud computing, mobility, and containerized applications has rendered the network perimeter less relevant, further highlighting the need for a better approach. The Zero Trust Framework has revolutionized how organizations think about cyber defense strategies. Zero Trust is not just a product or a service; it is a comprehensive approach that includes various principles, technologies, and strategies. It demands strict identity and continuous verification for every person and device attempting to access the corporate resources inside or outside the network perimeter. This is a paradigm shift from the traditional "trust but verify" or "Implicit Trust" model that often fails to address threats within the network. As we look toward the future, Zero Trust becomes increasingly crucial for organizations. As organizations' digital footprint expands, so does their attack surface. Zero Trust takes a proactive stance in this scenario, reducing the attack surface and minimizing the chances of unauthorized access and data breaches. Therefore, it is high time that organizations embrace this approach to secure their digital assets and ensure business continuity. This fresh perspective and new technologies can help organizations enhance their security posture and protect valuable assets from cyber threats, aligning new solutions according to the trends for 2024-2027:

• Identity-first Security • Security Segmentation and Beyond (Macro, Micro and Nano) • Automated Security Compliance and Continuous Monitoring • Artificial Intelligence and Machine Learning in Zero Trust • Security for the Internet of Things (IoT) and Edge Devices • Integration of Zero Trust in DevSecOps. • Extended Detection and Response (XDR)

"Zero Trust wasn't born out of a need to sell another security control or solution. It was born from a desire to solve a real enterprise issue; Zero Trust is focused on the simplicity and reality of how things are now.2"

Dr. Chase Cunningham, aka "Dr. Zero-Trust" What is the Zero Trust framework?

Zero Trust is a strategy and tactical cyber security framework. Its focus is on evolving perimeter-based defenses from wide, static perimeters to narrow, dynamic, and risk-based access controls for enterprise resources, independent of where they’re located. “Zero-Trust is the correct implementation of the “Least Privilege” principle, without it, “the trust” should be

considered as the major vulnerability3.” The new approach to the access-control, based on Zero Trust principles, considers different attributes such as identity, endpoint posture security, and the rights defined to access and consume the corporate data. In a recent Forrester publish: “The definition of the modern Zero-Trust”4 writed by David Holmes and Jess Burn where it is considered the premise that "assume you have already been compromised, and you don't know it" and having the data as the foundation for an effective "trust" strategy.

2 Zero Trust Security, An Enterprise Guide. Jason Garbis and Jerry W. Chapman. ISBN: 978-1-4842-6701-1 3 Cloud Security Alliance Zero Trust Advancement Center – URL: https://cloudsecurityalliance.org/zt/ 4 The Definition Of Modern Zero Trust - URL: https://www.forrester.com/report/the-zero-trust-extended-ztx- ecosystem/RES137210?ref_search=0_1672753830967

https://cloudsecurityalliance.org/zt/ https://www.forrester.com/report/the-zero-trust-extended-ztx-ecosystem/RES137210?ref_search=0_1672753830967 https://www.forrester.com/report/the-zero-trust-extended-ztx-ecosystem/RES137210?ref_search=0_1672753830967

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 3 The model defines thre important pillars: Entities untrusted by default, comprenhensive monitoring and least privilege ienforced, in the figure 2 we can oversee the updated definition in 2023.

Figure 1: The Modern Zero Trust Definition5 As main strategy, the principle of least privilege enforces that unauthorized users and systems will have no access to any enterprise resource (due to their low trust score). On the other hand, authorized users and systems will have access to the enterprise resources (assets) with only minimal access to the data according to their roles, permissions, and their trust score with the continuous verification. This is the consumer and provider security model where we have a "trust contract with least privilege and the continuous verification6" between the user and the asset,to consume and use enterprise data.

Figure 2: Consumer and Provider Model – Check Point Zero Trust Framework

5 Decoding The New Zero Trust Terminology – URL: Decoding The New Zero Trust Terminology (forrester.com) 6 Least Privilege Access vs. Zero Trust - URL: https://www.conductorone.com/glossary/least-privilege-access-vs-zero-trust/

https://www.forrester.com/blogs/decoding-the-new-zero-trust-terminology/ https://www.conductorone.com/glossary/least-privilege-access-vs-zero-trust/

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 4 The framework is focused on providing an evolutionary method for the organization's security programs and adoption ease. It also helps the organization to become more proactive and less reactive and to be more efficient in limiting and reducing the surface attack.

Figure 3: Check Point Zero-Trust Framework based on Risk Relationships Model7

This ensures the correct implementation of the security controls and countermeasures, thus reducing the business risk, potential economic impacts, loss of reputation, and being more efficient to respond in case of attack.

Figure 4: Zero Trust Framework – Business Process Centric8

7 Security Management and Risk Management Approach in Cybersecurity and Information Security Management - URL: Risk Relationships Model. Source: [19]. | Download Scientific Diagram (researchgate.net) 8 Zero Trust Extended by Forrester. URL: The Definition Of Modern Zero Trust (forrester.com)

https://www.researchgate.net/figure/Risk-Relationships-Model-Source-19_fig1_277009090 https://www.researchgate.net/figure/Risk-Relationships-Model-Source-19_fig1_277009090 https://www.forrester.com/blogs/the-definition-of-modern-zero-trust/

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 5

Why does the Zero Trust framework rely on Identity and Data?

Today, many organizations design their security strategy considering implicit trust only. This approach could be a dangerous vulnerability that malicious actors can exploit if we don't implement the least privilege principle to access the right corporate resources. Common problems in the organization are the lack of good Identity Governance and Administration (IGA9) to map the right roles and rights to access the enterprise data. In the following diagram, we can see how the new perimeter belongs to the Identity and Data categories. We can also see three diverse types of controls: network, host, and data.

Figure 5: The next perimeter: Identity and Data10

What is difference between the ZTNA versus ZT Framework?

Zero-trust network access (ZTNA)11 is a security concept that advocates for the strict verification of user and device identities before allowing access to network resources. It is based on the idea that organizations should not automatically trust any user or device on their network, even if they are inside the network perimeter. In a zero-trust model, access to resources is granted based on the user's or device's identity and the level of access they need to perform their job. This is often achieved through the use of multifactor authentication, which requires users to provide multiple forms of identification to access resources. ZTNA is designed to protect against threats such as malware, insider attacks, and unauthorized access to sensitive data. It is becoming increasingly popular as organizations move to remote work and adopt cloud- based services, which can make traditional network perimeter defenses less effective.

9 Identity, Governance and Administration (IGA) – URL: https://www.kuppingercole.com/research/lc81107/identity-governance-and- administration-2022 10 The evolution of Information Security Technologies by Dan Hitchcock – URL: http://movetheworld.wordpress.com 11 Definition of Zero-Trust Network Access by Gartner – URL: https://www.gartner.com/en/information-technology/glossary/zero-trust- network-access-ztna-

https://www.kuppingercole.com/research/lc81107/identity-governance-and-administration-2022 https://www.kuppingercole.com/research/lc81107/identity-governance-and-administration-2022 http://movetheworld.wordpress.com/ https://www.gartner.com/en/information-technology/glossary/zero-trust-network-access-ztna- https://www.gartner.com/en/information-technology/glossary/zero-trust-network-access-ztna-

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 6 A Zero-trust framework is a set of guidelines, principles, and best practices that organizations can follow to implement a zero-trust architecture (ZTA12). It provides a roadmap for building a security system that is based on the zero-trust network access (ZTNA13), Zero-Trust Network Security (ZTNS14), Zero-Trust Container Architecture (ZTCA15), Zero-Trust DevOps16 concepts, which advocates for the strict verification of user, devices and applications identities before allowing access to network resources. A zero-trust framework typically includes guidelines for identifying and authenticating users and devices, setting access controls, and implementing network segmentation (Macro, Micro and Nano). It may also include recommendations for implementing multifactor authentication, encryption, and other security measures to protect against threats such as malware, insider attacks, and unauthorized access to sensitive data. The goal of a zero-trust framework is to help organizations effectively implement a zero-trust architecture, which can protect against threats and improve security in the face of increasingly complex and evolving cyber threats.

Why should a Zero Trust framework be business-driven? The zero-trust framework should be business-driven because it is designed to address the specific security needs of an organization. While a zero-trust architecture (ZTA) can provide a number of benefits, such as improved security and reduced risk of data breaches, it is important for the framework to be tailored to the unique needs of the business. By focusing on the specific business needs and goals of an organization, a zero-trust framework can ensure that the security measures implemented are effective and relevant. This can help to improve the overall security posture of the organization and better protect against cyber threats. Additionally, a business-driven zero-trust framework can help to ensure that the security measures implemented do not disrupt or hinder the normal operations of the business. By considering the needs and constraints of the business, the framework can be designed to minimize disruptions and ensure that the security measures are easily integrated into the organization's existing processes and systems. Data enables the organization to identify business opportunities, predict business trends, provide analytics to the business related to consumer behavior and the market conditions for trading. Data, therefore, provides intrinsic value for the business; however, in some cases, it can be easily exposed. Forrester provides an essential reminder about data, illustrating its "as the value" importance.

12 Zero-Trust Architecture by NIST - https://www.nist.gov/publications/zero-trust-architecture 13 Zero-Trust Network Access - https://www.gartner.com/en/information-technology/glossary/zero-trust-network-access-ztna- 14 By 2023, 60% Of Enterprises Will Use the Zero Trust Security Model – URL: https://infosecwriteups.com/why-is-the-zero-trust- security-model-effective-93e853bee9c5 15 Zero Trust Container Architecture (ZTCA) – URL: https://papers.academic-conferences.org/index.php/iccws/article/view/35 16 Securing DevOps environments for Zero Trust – URL: https://learn.microsoft.com/en-us/security/zero-trust/develop/secure-devops- environments-zero-trust

https://www.nist.gov/publications/zero-trust-architecture https://www.gartner.com/en/information-technology/glossary/zero-trust-network-access-ztna- https://infosecwriteups.com/why-is-the-zero-trust-security-model-effective-93e853bee9c5 https://infosecwriteups.com/why-is-the-zero-trust-security-model-effective-93e853bee9c5 https://papers.academic-conferences.org/index.php/iccws/article/view/35 https://learn.microsoft.com/en-us/security/zero-trust/develop/secure-devops-environments-zero-trust https://learn.microsoft.com/en-us/security/zero-trust/develop/secure-devops-environments-zero-trust

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 7

Figure 6: Business data asset and the "value" created by the workload "Data assets are essential for businesses to grow and prosper17," where the workloads host, store and run those assets should be protected. If we don't know how the data is processed, transferred, and consumed, malicious actors will frequently infiltrate the organization to extract and use the data for their own purposes.

How to communicate the Zero-Trust business value? Communicating the business value of Zero Trust involves articulating its ability to mitigate cybersecurity risks, ensure regulatory compliance, and foster operational agility. Challenges include the paradigm shift to a "never trust, always verify with the continuous verification assuming the breach" mentality, which requires investment in technology and training. Advantages include reducing data breaches, cost efficiency through optimized resource allocation, and an enhanced competitive position by showcasing a robust cybersecurity posture. Through a clear communication strategy, executives can align the organization towards understanding and embracing the advantages of Zero Trust despite the challenges, making it a cornerstone of the cybersecurity strategy. In the Whitepaper “Communicating the Business Value of Zero-Trust”18 published by Cloud Security Alliance in August 2023, it is suggested to follow the next principles: • Beginning with the End in Mind

• Establish a clear vision of the organization’s desired direction and destination at the outset of the Zero Trust journey

• Breaches Happen • Shift Mindset from being 100% secure to being resilient, resulting in the following benefits:

• Limiting the blast radius of affected devices when a breach occurs through the right Security Segmentation strategies

• Reducing a hacker’s ability to perform reconnaissance and move laterally across the enterprise by implementing Threat Modeling

• Reducing the impact by limiting what assets can be damaged or stolen by a single event implementing Risk Management

• Risk Management • Understand the organization’s risk appetite to reduce Inherent Risk to acceptable levels • Use risk-based prioritization to understand and identify gaps that must be addressed • Start small and focus on quick wins to bolster security posture and build momentum for the Zero

Trust initiative

17 Why data is valuable for the Business? - URL: Why is data important for your business? – MajestEYE 18 Communicating the Zero-Trust Business Value – URL: https://cloudsecurityalliance.org/artifacts/communicating-the-business-value- of-zero-trust/

https://www.majesteye.com/why-is-data-important-for-your-business/ https://cloudsecurityalliance.org/artifacts/communicating-the-business-value-of-zero-trust/ https://cloudsecurityalliance.org/artifacts/communicating-the-business-value-of-zero-trust/

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 8 • Leverage pilot metrics to demonstrate business value and obtain buy-in from leadership

Zero Trust as part of the Enterprise Architecture Enterprise architecture is a discipline that provides a methodology to capture the relationships and interactions between business domain elements as described by their processes. This includes functions, applications, events, data, and technologies. The Zero Trust framework is interdisciplinary because it can connect the business architecture and the information and technology architecture, providing a unified approach to protecting the enterprise assets and enabling the Zero-Trust Framework. The Zero-trust architecture (ZTA) can be an important part of an enterprise architecture, which is a framework that defines the overall structure and operation of an organization. Enterprise architecture typically includes a number of different components, including business processes, information systems, and technology infrastructure. Incorporating a zero-trust architecture into the enterprise architecture19 can help to improve the security posture of the organization and better protect against cyber threats. This can be achieved through the implementation of technologies such as multifactor authentication, encryption, and network segmentation, which can help to control access to sensitive resources and prevent unauthorized access. A zero-trust architecture can also help to ensure that the organization's security measures are aligned with its business goals and objectives. By considering the needs of the business and tailoring the security measures to meet those needs, a zero-trust architecture can help to ensure that the security measures are effective and do not disrupt the normal operations of the organization. Overall, incorporating a zero-trust architecture into the enterprise architecture can help to ensure that the organization's security measures are effective, aligned with business goals, and do not disrupt normal operations.

Figure 7: Enterprise architecture and Zero Trust integrated – PricewaterhouseCoopers

Let's describe the relationships between the business and the information and technology architecture roles: Business architecture / enterprise architecture

• Business architecture contains the general description of a system, its purpose, vital functions, active elements, critical processes, and the nature of the interaction among them. In business architecture, we also have all the requirements for data and IT governance and can define the actors and the roles that access the business services, processes, and controls, as required.

Here is where the consumer-provider trust contract starts modeling to map properly the transaction flows between the business applications and enterprise data.

19 Zero-Trust Architecture: A Paradigm shift in Cybersecurity and privacy – URL: https://www.pwc.com/sg/en/publications/assets/page/zero-trust-architecture.pdf

https://www.pwc.com/sg/en/publications/assets/page/zero-trust-architecture.pdf

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 9 Information and technology architecture

• Information and technology architecture refers to the business processes and policies, system structure, technical structure, and product technologies required for a business or an information system. Here we have the applications and functions associated with securely transforming the data in the information category to be "consumed" by the users (humans and machines). Then, the natural step is the development of a technical blueprint regarding the arrangement, interaction mapping of all the transactional flows, and interdependence of all elements to meet system-relevant requirements.

Zero Trust Maturity Model and implementation In this section, we will discuss how the maturity assessment is the most important step in the definition of the priorities of the journey. This step is a key element because we can avoid or remove multiple duplicities. The Zero Trust Maturity Model was published by CISA (Cybersecurity and Infrastructure Security Agency - Cybersecurity Division)20 in April 2023, it serves as a roadmap for government agencies and organizations transitioning to a zero trust architecture. It's designed to aid in strategizing and implementing zero trust principles, while also highlighting how Consulting Services can facilitate this transition. The model is structured around five main pillars and four cross-cutting capabilities, Traidtional to Optimal. Each pillar elucidates stages of maturity from traditional methods to optimal zero trust implementations Additionally, the maturity analysis of "as-is" can provide us with the roadmap "to be" to accomplish the Zero Trust objectives. Maturity Assessment is crucial in setting priorities as it helps organizations:

• Identify Gaps: Understand current capabilities and weaknesses, pinpointing areas needing improvement.

• Resource Allocation: Ensure resources are strategically invested in areas that need them most, enhancing efficiency.

• Risk Management: Assess how current practices align with risk appetite, adjusting processes to mitigate vulnerabilities effectively.

• Goal Alignment: Ensure cybersecurity initiatives align with broader organizational goals, providing clear direction.

• Progress Tracking: Establish a baseline to measure progress over time, ensuring efforts yield tangible improvements in security posture.

Implementation of a zero-trust maturity model typically involves conducting a review of the organization's current security practices and identifying areas where the organization is already using zero-trust principles. This can include evaluating the organization's use of technologies such as multifactor authentication, encryption, and network segmentation, as well as its processes for identifying and authenticating users and devices. Based on the results of this review, the organization can then identify areas where it can improve its zero-trust implementation and develop a plan to move to the next level of maturity. This process can be ongoing, with the organization periodically reviewing and updating its zero-trust maturity model as its security needs and practices evolve. Overall, a zero-trust maturity model can help organizations to assess and improve their zero-trust architecture, ensuring that their security measures are effective and aligned with their business goals.

Zero Trust maturity assessment

20 Zero-Trust Maturity Model 2.0 – URL: https://www.cisa.gov/sites/default/files/2023- 04/zero_trust_maturity_model_v2_508.pdf

https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 10 The business must understand its current maturity level, engaging in organization-wide reviews to conduct a thorough and efficient analysis. The analysis is not only technical, but it should also account for the people, processes, and technologies in place that contribute to the Zero Trust pillars.

Let's start with the maturity assessment and deployment phases to describe how Zero Trust should be addressed properly.

Figure 8: Maturity assessment and roadmap to implement the desired state. Source: Forrester & Cloud Security Alliance The result in the analysis "as-is" provides the differential in the baseline and target points or suggested architecture "to-be" in the gap assessment. This gap assessment includes specific areas in each pillar that the Zero Trust roadmap will address to improve the current state. Such will be done methodically and gradually over one to five years with different security projects in place. Importantly, the roadmap should be adapted to the business requirements and reality to avoid an impact on performance, which was previously a concern for security teams. Consequently, security teams and business stakeholders will be aligned.

Zero Trust maturity modeling: from implicit to explicit trust

As the business stakeholders gain more visibility into the current state of their maturity level, it’s possible to identify and incorporate into their architecture new solutions that address the gaps. This will also advance their maturity after they define a desired maturity level according to their risk appetite considering the Identities for Human & Machines to have access to the corporate resources and the machine-to-machine communication.

Figure 9: The Risk-Driven approach between the Identities, Applications and Data

A maturity level can be defined according to the following levels:

1. Implicit Trust

It refers to the assumption that a person or entity can be trusted without explicit evidence or verification.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 11 In the context of cybersecurity, implicit trust can be a significant risk and vulnerability. For example, an organization may implicitly trust its employees and grant them access to sensitive resources without verifying their identity or ensuring that they have the necessary permissions. This can lead to security breaches if an employee's account is compromised or if they misuse their access privileges. This trust level is associated with manual configurations, static security policies and silos in the security strategy. Authentication sources are not federated and are limited. In this stage, the organization needs to work on the documentation of mapping the users versus the applications and data. Additionally, they also need to map the transactional flows between the applications.

2. Contextual Trust It refers to the trust that is specific to a particular context or situation. It is a type of trust that is conditional, meaning that it is dependent on the circumstances in which it is exercised. In the context of cybersecurity, contrasted with implicit trust, it is the trust that is not dependent on specific circumstances and particularly useful in situations where users needs to collaborate or work together on a short-term basis, or when they need to rely on someone to perform a specific task or service. This trust level is associated with implementing the initial stages of the least-privilege in several applications. The organization now has more clarity about the importance of the "value of the data", and the evolution from the network segmentation can be moved to the security segmentation. There is also more focus on users, applications, and data.

3. Explicit Trust

It refers to trust that is based on evidence or verification. It is the opposite of implicit trust, which is based on assumptions or relationships. In the context of cybersecurity, explicit trust is often based on the verification of a user's or device's identity through methods such as multifactor authentication, which requires users to provide multiple forms of identification to access resources. This helps to ensure that only authorized users and devices can access sensitive resources and reduces the risk of security breaches. This trust level is associated with automated assigning of attributes to assets and resources. Dynamic security policies are also implemented with automated triggers in case of a security violation. Furthermore, a dynamic least-privilege, according to the trust score, is implemented, and open standards, or APIs, are used for cross-pillar interoperability through centralized visibility. Explicit trust is an important principle in a zero-trust architecture (ZTA), which is a security design approach that advocates for the strict verification of user and device identities before granting access to network resources. By relying on explicit trust, organizations can better protect against threats such as malware, insider attacks, and unauthorized access to data.

Figure 10: The Implicit Trust Model

Figure 11: The Explicit Trus Model

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 12 In the following, figure we show the difference between the phases to illustrate the evolution from "implicit trust" to "explicit trust".

Figure 12: CISA 2.0 – ZeroTrust Maturity Model phases – From implicit to explicit trust

Strategic, tactical, and operational roles To properly build Zero Trust in the organization, it’s essential to define the strategic, tactical, and operational roles. This is why the digital and cloud transformation starts with the top management, as they handle the business goals and drivers. From an information security perspective, the CEO focuses on business growth, reputation, and aligning the needs of the corporate governance requirements. The CFO oversees efficient return of investment, which is why the strategy should offer improvements in predictability and consistency. Meanwhile, the COO is focused on business performance, which enables process improvement. Why is it important? Defining Zero Trust as the only technological strategy will fail due to the investment required by integrations, deployment, and support of different vendors. The Zero Trust strategies will fail if these primary stakeholders don't adequately define the strategy for the organization. Therefore, in this stage it’s recommended that an enterprise security maturity assessment is performed to review how the security posture within the organization, and to define the priorities and technological requirements.

Figure 13: Strategies for the Zero Trust framework

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 13 Once we have the maturity assessment results and can clearly define the security posture of the organization, the CIO and CISO should work on clarifying the Zero Trust enterprise strategy with priorities, timelines, and budgets in mind.

Figure 14: Tactical roles for the Zero Trust framework A maturity assessment provides the right approach and focus to evaluate and test the right technology. According to the maturity level, the organization needs to fix different gaps, for example, the security posture of devices. Another example is the risk associated with the software supply chain: potential vulnerabilities are detected and should be adequately addressed to fix them. In practice, a typical mistake that organizations make is considering technological tools as the final solution in the Zero Trust strategy. Gartner suggests that before consulting a single vendor, a process evaluation should take place to outline what needs to be optimized to appropriately align the priorities and timelines for implementing the potential solutions. Here, the CTO, together with solution architects, maps the low-level design with the business requirements, to align them appropriately. This is the right path because, typically, the security requirements start from "bottom to top", which demands justification per each technology or security vendor. However, having the approach from "top to bottom" provides the "complete" vision which aligns the business requirements with the technology integrations, deployment, and operations.

Figure 15: Transformational roles for the Zero Trust framework

In the low-level design, the solution architects define all the required configurations and the potential evaluations for the security vendors to implement a good technology consolidation.

Let's place all the blocks together with the Check Point vision of the Zero Trust Enterprise Framework.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 14

Figure 16: Zero Trust Framework, strategic initiatives and tactical projects under the SABSA Framework21

Digital & cloud transformation demands agility, sustainability, and simplifying the service user experience, while avoiding duplication of business processes with their relevant security controls, and improving the budget (CAPEX/OPEX) spending. Keep in mind that considering the global challenges in energy consumption, Zero Trust can also help reduce the consumption of critical enterprise resources. Additionally, it can increase the business’ resiliency by enabling the principles of least-privilege, continuous verifications, security posture reviews, and compliance. These are natural outcomes of security activities, and provide a significant level of confidence and visibility, controls, and response processes.

Remember that the Zero Trust framework SHOULD be adapted to the business needs and not vice versa. Trying to implement strict requirements to follow the industry frameworks could lead to an implementation problem, false expectations, and loss in the business objectives.

How to land a tactical Zero Trust project? Implementing a Zero Trust security model can be a significant undertaking for any organization, and it is important to approach it in a strategic and tactical way in order to ensure a successful outcome. Here are some steps you can take to land a tactical Zero Trust project:

1. Define the goals with the End in mind: Clearly articulate the specific security challenges that you are trying to address with the Zero Trust model, and define the outcomes you hope to achieve.

21 Sherwood Applied Business Security Architecture Framework - URL: https://sabsa.org/sabsa-executive-summary/

https://sabsa.org/sabsa-executive-summary/

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 15 2. Assess your current security posture and maturity: Conduct a thorough Zero-Trust assessment of

your current security posture to identify your current strengths and weaknesses, and to determine where you will need to make changes in order to implement the Zero Trust model.

3. Identify stakeholders: Identify the key stakeholders in your organization who will be affected by the Zero

Trust implementation, and engage with them to understand their concerns and needs.

4. Develop a roadmap with the priorities: Develop a roadmap that outlines the specific steps and resources required to implement the Zero Trust model, including any changes to processes, technologies, or organizational structures.

5. Communicate and educate the organiztion: Communicate the benefits and implications of the Zero

Trust model to all relevant stakeholders, and educate them on how it will impact their day-to-day work.

6. Pilot and test: Consider piloting the Zero Trust model in a specific area or with a specific group of users before rolling it out organization-wide. This will allow you to test the model and make any necessary adjustments before fully implementing it.

7. Monitor and adjust: Continuously monitor the effectiveness of the Zero Trust model and make any

necessary adjustments to ensure that it is meeting your security goals and needs. A tactical Zero Trust project is defined by the timelines (normally Gantt charts) required to implement different security controls to solve a problem or gap after the maturity assessment analysis and the priorities definition. The most important part of the tactical project is to define the potential solutions that should be harmonized in the organization, the risk appetite, and the most important business priorities. We must keep in mind that the strategic initiatives need to start somewhere, however, it’s not recommended to start at a large scale as it will complicate the implementation and could lead to a lack of confidence and failed projects which waste resources and money. “The key to being successful in a Zero Trust project is to include identity management.

Application Management and the Enterprise architecture teams.” In the following table we have a summary defining the activities and roles within a tactical Zero Trust project.

Step Zero Trust tactical team, solution architect, and technical architects activities

Enterprise architects

1

Describe the Zero Trust gaps detected in the applications, networks, users, devices, and compliance requirements.

2

Research and evaluate different technological solutions.

3

Review the approach and the suggested architecture to validate if it is aligned with the business objectives. Validate the budget owners, application owners, data owners, operations, compliance, and the tactical team’s path from "as-is" to "to-be". Try to avoid silos in Zero Trust projects.

4

PoC candidate for different Zero Trust platforms or solutions in lab environments defining different use cases to protect users, devices, networks, workloads, and data.

5

Present the PoC results to the stakeholders and let the business choose a consolidated platform, plus validate the security architecture.

6

Preproduction pilot – validate the alignment with the business needs, architecture, and fill security gaps.

7

Analyze the preproduction pilot lessons, mistakes in the configurations, and evaluate the go/no-gos. Rollout plan should be reviewed and approved with the operations team to define "before" and "after.

8 Full production implementation for the whole organization according to the associated pillar (users, devices, networks, workloads, data).

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 16 9 Babysitting surveillance in the production environment

and the performance of Zero Trust security controls.

Table 1: Tactical Zero Trust project: Roles and responsibilities22

Transforming Zero Trust with Check Point Infinity Global Services Check Point Infinity Global Services23 understands that implementing Zero Trust practices in an enterprise is a complex undertaking, and knows the value our customers place on our architectural workshops. Because of this, Check Point now offers an enterprise Zero Trust consultancy service specifically around the different maturity phases and how to create an accurate roadmap. Check Point’s Infinity Global Services aims to fill this gap by providing end-to-end security offerings that help organizations prevent advanced threats, respond to widespread attacks, and enhance their cybersecurity practices and controls.

Figure 17: Infinity Global Services

• Assess o Assess the ZT & CSMA Maturity Levels o Analysis of Maturity Levels o Review existing design/architecture AS-IS o Define the Target Zero-Trust Strategy and CSMA architecture (TO-BE)

• Optimize o Define an Implementation Roadmap o Create LLD o Implement Infinity CSMA with Check Point Zero Trust Platform

• Master o Security awareness across all Zero Trust domains o Check Point ZT platform operating training

• Respond o IR service o MDR

The service is based on the core principles defined in the Check Point Enterprise Security Framework (CESF2). You can find more details here: https://www.checkpoint.com/support-services/security-consulting/ The Check Point Enterprise Security Framework is built around the architectural methodology of SABSA, and the design principles of Zero Trust. The CESF2 allows Check Point to translate business requirements into practical security solutions.

22 Zero-Trust Security, An Enterprise Guide by Jason Garbis, Jerry W. Chapman, ISBN: 978-1-4842-6701-1 23 Check Point Infinity Global Services – URL: https://www.checkpoint.com/services/infinity- global/#:~:text=Check%20Point%20Infinity%20Global%20Services%20Check%20Point%20Infinity,widespread%20attacks%20and%20 enhance%20your%20security%20resilience%20strategy

https://www.checkpoint.com/support-services/security-consulting/ https://www.checkpoint.com/services/infinity-global/#:%7E:text=Check%20Point%20Infinity%20Global%20Services%20Check%20Point%20Infinity,widespread%20attacks%20and%20enhance%20your%20security%20resilience%20strategy https://www.checkpoint.com/services/infinity-global/#:%7E:text=Check%20Point%20Infinity%20Global%20Services%20Check%20Point%20Infinity,widespread%20attacks%20and%20enhance%20your%20security%20resilience%20strategy https://www.checkpoint.com/services/infinity-global/#:%7E:text=Check%20Point%20Infinity%20Global%20Services%20Check%20Point%20Infinity,widespread%20attacks%20and%20enhance%20your%20security%20resilience%20strategy

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 17

Figure 18: Check Point Enterprise Security Framework for enterprise architecture24

Check Point has created a set of transformation principles to help enterprises shape their cloud strategy and transformation process. We have captured these into a framework that we will present below. These high-level architectural principles also form the foundation of our “Infinity Global Services, Zero Trust Advisory & Maturity Assessment Services”. They are designed to support planning and execution, and to give some structure to the overall process. Unlike other frameworks, Check Point’s Zero-Trust transformation framework is a collection of principles, analyses, and recommendations presented as a single process. It's our experience that enterprises are usually at very different stages in the process. Consequently, when we discuss the topics below with customers, some topics are well-developed and allow us to move directly to recommendations. In contrast, others require a deeper analysis, and some are mainly aspirational. The overall goal of the framework is to understand our customer’s current position, explain our understanding of a holistic target architecture, and make recommendations that help them achieve their strategic vision.

Check Point has identified the following key principles for Zero Trust implementation:

24 Check Point Enterprise Security Framework – URL: https://www.checkpoint.com/downloads/products/checkpoint-enterprise-security- framework-whitepaper.pdf

Focus on Business

Outcomes + Define your protect surface Map all the transaction flows + Architect and Design the Zero-Trust + Create the Zero-Trust Policy + Visualize and Monitor all

Enforcement Points and Maintain

Zero Trust Architecture Process

Figure 19: The Zero Trust Workshop model (DAAS)

https://www.checkpoint.com/downloads/products/checkpoint-enterprise-security-framework-whitepaper.pdf https://www.checkpoint.com/downloads/products/checkpoint-enterprise-security-framework-whitepaper.pdf

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 18

Zero Trust Advisory Service n the modern world of digital transformation, there is a significant change in how security should be applied across different domains. Organizational leadership is increasingly looking to adopt Zero Trust principles to secure their enterprise services. The Journey to adopt Zero Trust across the board can be challenging and requires buying in and coordination on many levels within the organization. Zero Trust Advisory Services are aimed at helping leaders understand the importance of Zero Trust, its key components, and how it can be tailored to their organization's needs. It's a proactive approach to cybersecurity that can enhance security, compliance, and business resilience in an increasingly digital and interconnected world.

• Understanding Zero-Trust • The Need for Zero Trust • Key Componentes of Zero-Trust • Tailoring Zero Trust to Your Organization • Business Benefits and communicating the business value • Investment and Budgeting Zero-Trust • Cultural Shift

The benefit of the Zero Trust Advisory Services is to offer a holistic approach to cybersecurity that provides organizations with the guidance, expertise, and strategic framework needed to bolster their security defenses, reduce risk, and adapt to the evolving threat landscape.

Zero Trust Maturity Assessment & Architecture Service The Zero-Trust Maturity Model enables us to guide the strategic implementation of Zero- Trust principles. The process begins with interviews with key stakeholders and moves into a detailed review of the current and future security posture and network topology. A key component of the workshop is to fully understand the drivers and the challenges to Zero-Trust journey, starting from the business and the technology perspective. It provides a comprehensive approach to cybersecurity that promotes proactive risk management, continuous monitoring, and adaptive defense mechanisms, ultimately enhancing an organization's ability to withstand and respond to evolving cyber threats.

“Information Security is a journey and not a destination.25”

25 Cybersecurity Is A Journey, Not A Destination – URL: https://www.forbes.com/sites/forbesbooksauthors/2021/10/11/cybersecurity-is- a-journey-not-a-destination/?sh=6cf885a33a91

Figure 20: Zero-Trust Advisory Service

Figure 21: Zero-Trust Dasboard

https://www.forbes.com/sites/forbesbooksauthors/2021/10/11/cybersecurity-is-a-journey-not-a-destination/?sh=6cf885a33a91 https://www.forbes.com/sites/forbesbooksauthors/2021/10/11/cybersecurity-is-a-journey-not-a-destination/?sh=6cf885a33a91

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 19 Our service is focused on:

• Assessment Framework: To use standardized frameworks or models to conduct the assessment, such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework or the Zero Trust Maturity Model by CISA.

• Data Collection: The assessment involves gathering data on various aspects of the organization's cybersecurity, including network architecture, access controls, identity management, and incident response.

• Scoring and Analysis: Once the data is collected, it is scored and analyzed to determine the organization's current maturity level in different Zero Trust domains.

• Gap Analysis: The assessment results help identify gaps and weaknesses in the existing security measures and provide insights into areas that need improvement.

• Recommendations and Architecture: Based on the findings, organizations receive recommendations for enhancing their Zero Trust posture, along with a roadmap for implementation.

Benefits

• Identify the crown jewels: If you're beginning, we'll help you identify high-priority areas for protection. • Assess your current state (AS-IS): We'll review your existing identity and access control environment

and policies to determine how they fit in a zero-trust framework. • Visualize what's next (TO-BE): We'll help you prioritize zero trust strategy and implementation

milestones to align with business objectives. • Plan the deployment: Receive a detailed plan and roadmap with defined next steps for implementation

readiness and actual deployment.

Reporting and Strategic Zero-Trust Planning We believe this process is an effective means of communicating a long-term vision for better security architecture. For this message to be accurately delivered, the workshop process culminates in a bespoke report outlining key design concepts and recommendations. Upon completion, we will deliver an architectural report that includes a customized transformation blueprint and recommendations that we align with your business objectives.

“Zero Trust Architecture requires careful planning and a long-term vision”

Figure 22: Roadmap Planning for Zero-Trust elements26

26 Check Point Software Security Consulting – URL: https://www.checkpoint.com/support-services/security-consulting/#zero-trust

https://www.checkpoint.com/support-services/security-consulting/#zero-trust

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 20 It’s not enough to choose a collection of cloud technologies without having a solid understanding of the why, what, and how they will be used. From experience, it’s known that enterprises see value in a more structured approach, which is why Check Point has developed a unique enterprise security framework. The digital future is challenged by existing long-held operational models and established fundamental business processes. Check Point believes that to navigate these organizations should adopt a structured, methodological approach that translates defined business requirements into strategic security solutions.

Zero Trust Reference Architecture In the previous section, we discussed how Zero Trust should be focused on as a business-driven framework. This section will describe the architectural concepts and how several technological components can be integrated. In the following diagram, we will illustrate how the Zero Trust architecture is aligned with NIST. Typically, this model has been focused on identity-aware architectures; however, more technological components can be integrated into this model, helping to avoid duplication in the security needs and optimizing the enterprise security architecture.

Figure 23: NIST Zero Trust model

Let's define the main concepts: • Policy Enforcement Point (PEP): PEP is the interface of the whole environment to the outside world. It

receives access requests, evaluates them with the help of the other actors and permits or denies access to the resource. The firewall or endpoint is an excellent example of an enforcement point, and, in the Zero Trust pillar section, we will describe more components considered as enforcement points.

• Policy Decision Point (PDP): PDP is the main decision point for access requests. It collects all the necessary information from other actors and concludes with a decision. Here we can define the ‘allow’ or ‘deny’ access to the enterprise resources according to the trust score of the user.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 21 • Policy Engine (PE): PE decides whether to grant access to any resource within the network. It relies on

policies orchestrated by the enterprise's security team and data from external sources. Access is then granted, denied, or revoked based on the parameters defined by the enterprise. The policy engine communicates with a policy administrator component that executes the decision.

• Policy Administration Point (PAP): PAP is the repository for the policies (Explicit Trust) and provides the guidelines for the Policy Decision Point (PDP).

• Policy Information Point (PIP): PIP is the point where the necessary attributes for the policy evaluation are retrieved from several external or internal actors. The attributes can be retrieved from the resource to be accessed, environment (e.g., time), subjects, etc.

Core components In the previous architecture described, we will now integrate the different elements associated with the control plane and the data plane.

o Control Plane

 Policy Decision Point (PDP)  Policy Administration Point (PAP)

o Data Plane  Policy Enforcement (PEP)  Policy Information Points (PIP)

In the context of Zero-Trust, the principle of least privilege and continuous verification should be implemented in the identity layer, providing a trust score according to the user/session risk. The endpoints or ‘devices’ are critical elements to allow the ‘user’ access to the enterprise resources. Here, the asset inventory is a key source of telemetry used to understand the behavior, which in turn helps us to understand efficiently what is happening when we have a connection.

Figure 24: NIST Zero Trust reference architecture

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 22 NIST has defined six scenarios to implement successful Zero Trust policies within the organization:

• Scenario 1: Employee access to corporate resources • Scenario 2: Employee access to internet resources • Scenario 3: Contractor access to corporate and internet resources • Scenario 4: Inter-server communication within the enterprise • Scenario 5: Cross-enterprise collaboration with business partners • Scenario 6: Develop trust score/confidence level with corporate resources.

In the following section, we will describe the Zero Trust pillars and how the security controls can be mapped and aligned with them.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 23

Zero Trust architecture pillars In this section, we will describe the Zero Trust pillars in more detail; considering the analysis of the technological components. This approach is essential to define the priorities to implement it.

Figure 25: Zero-Trust pillars and capabilities ZERO TRUST USERS (Persons/Non Persons): Using different authentication layers to ‘deny identity’ to hackers trying to steal digital assets, is the last line of defense for any Zero Trust strategy. The focus is to limit and strictly enforce users' access and secure them as they interact with the internet. This encompasses all the technologies necessary for authenticating users and continuously monitoring and governing their access and privileges. It also includes the technologies for securing and protecting users' interactions, as traditional web gateway solutions do.

Figure 26: Zero Trust identities and data

ZERO TRUST DEVICES: Secure, control, and isolate every device on your network. Network-enabled device technologies have introduced a massive potential compromise for networks and enterprises. Security teams must be able to isolate, secure, and always control every device on the web.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 24

Figure 27: Zero Trust devices

Note: Zero Trust Network Access is aligned with the pillars related to the users, devices, and part of the network pillar.

Figure 28: From remote access to Zero Trust network access for Users and Devices

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 25 ZERO TRUST NETWORKS: Reduce the risk of lateral movement with micro and nano perimeters and identity- based policies and create security zones through the macrosegmentation. This provides the ability to segment, isolate, and control the network, a pivotal point of control for the Zero Trust framework for Private, Public, Hybrid Networks.

Figure 29: Private and public cloud segmentation

In the Implicit Trust Model, the segmentation was only focused on the network perspective, however in the transformation process to explicit trust, now the hybrid cloud should be segmented according to the following principles:

• Vulnerability-based Segmentation27 o Focused on reducing the speed of breaches by reducing exposure of the vulnerable data.

• Application-based Segmentation28 o Focused on segregating individual applications with individual security segments, for

example ERP, Financial or CRM services. • User-based Segmentation29

o Focused on laying down utmost security for a particular user logging into a particular workload or service.

• Location-based Segmentation30 o Focused on segregating each security segment with each location of the Datacenter or

public cloud (IaaS/PaaS).

27 How network segmentation mitigates unauthorized access risk – URL: https://www.csoonline.com/article/3587324/how-network- segmentation-mitigates-unauthorized-access-risk.html 28 Application Segmentation - https://www.tigera.io/learn/guides/zero-trust/application-segmentation/ 29 What is user segmentation? – URL: https://www.pendo.io/glossary/user-segmentation/ 30 Network segmentation in modern environments - https://www.hashicorp.com/blog/network-segmentation-in-modern-environments

https://www.csoonline.com/article/3587324/how-network-segmentation-mitigates-unauthorized-access-risk.html https://www.csoonline.com/article/3587324/how-network-segmentation-mitigates-unauthorized-access-risk.html https://www.tigera.io/learn/guides/zero-trust/application-segmentation/ https://www.pendo.io/glossary/user-segmentation/

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 26 ZERO TRUST WORKLOAD: Workload refers to the entire application stack; from the application layer to the hypervisor, or self-contained components of processing such as containers and virtual machines.

Figure 30: Evolution of the workloads; from bare metal to domain microservices.

The workloads make up the logical functions that drive the business and are typically located in the frontend, middleware, and backend segments/layers. Here, conjunction runs the business process to provide a service or product. The connections, applications, and components must be treated as a threat vector and must have Zero Trust controls and the right technologies applied to them.

Figure 31: Zero Trust for domain/microservices and functions – 4C model31.

ZERO TRUST DATA: Also defined as the "value" of the organization being considered at the center of any Zero Trust strategy. To protect the data, the policy model should be capable of enforcing contextual access policies where possible. This is important when building the trust contract between the user and the data under the principle of explicit trust.

31 Overview of Cloud Native Security – URL: https://kubernetes.io/docs/concepts/security/overview/

https://kubernetes.io/docs/concepts/security/overview/

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 27 This is a core pillar of a Zero Trust strategy: securing and managing the data, categorizing, developing data classification schemas, and encrypting data at rest and in transit. ZERO-TRUST VISIBILITY & ANALYTICS: Enable complete threat visibility with a single view of security risks using advanced analytics platforms. For example, User and Entities Behavior Analytics (UEBA) provide a comprehensive overview of how users interact with the business process and the potential impacts of non- common behavior. This area of the extended Zero Trust ecosystem helps tools, platforms, or systems empower the security analyst accurately to observe the threats present, and implement defenses more intelligently. ZERO-TRUST AUTOMATION & ORCHESTRATION: Allows tasks and processes to use flexible APIs and rich third-party integrations. This creates the ability and speed to have positive command and control of the business process's many components and is used as part of the Zero Trust strategy as a vital tool for operations.

Figure 32: Zero Trust architecture for visibility, analytics, automation, and orchestration pillars based in the DoD Zero-Trust Reference Architecture

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 28

Zero Trust operational model In the previous sections we described the different pillars and technologies involved; however, how can Zero Trust be integrated within the operational model in simple words? The U.S. Department of Defense designed the operational model described in the following diagram to help explain.

Figure 33: Zero Trust operational model, Source: DoD32

Previously we described the service contract model between the user and the application/data in the NIST model. Now, we will explain how this flow interacts with different layers to provide the ‘trust.’

Let's start with the first block related to client and identity assurance and enforcement. On the left we have two subjects: a human or a machine. In the authentication decision point, we evaluate the user's identity (human or machine) and the relevant device attempting to be connected to the application and data. However, the authorization decision examines the requests to access resources. It compares them with the applicable policy that applies to all requests for accessing a specific resource to determine the particular access that should be granted.

Also, the device should provide the device posture showing the compliance doing the enforcement in the patches and hardened configuration(s) applied to devices before they can connect to the enterprise network and be updated continually with their status (trust score). Then, using PAM (Privileged Access Management), it’s possible to secure, control, manage, and monitor privileged access to critical assets.

This is the principle of Explicit Trust: The user and device-relevant authorizations are the first stage in conditional access to the applications; the enterprise data (the business value) through the Kipling Method33.

32 Department of Defense (DOD) Zero Trust Reference Architecture – URL: https://cloudsecurityalliance.org/artifacts/dod-zero-trust- reference-architecture/ 33 The Kipling Method – URL: https://projectofhow.com/methods/the-kipling- method/#:~:text=The%20Kipling%20method%20let%20you,and%20run%20out%20of%20ideas.

https://cloudsecurityalliance.org/artifacts/dod-zero-trust-reference-architecture/ https://cloudsecurityalliance.org/artifacts/dod-zero-trust-reference-architecture/ https://projectofhow.com/methods/the-kipling-method/#:%7E:text=The%20Kipling%20method%20let%20you,and%20run%20out%20of%20ideas https://projectofhow.com/methods/the-kipling-method/#:%7E:text=The%20Kipling%20method%20let%20you,and%20run%20out%20of%20ideas

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 29 The Kipling Method is a cybersecurity approach based on the principle of least privilege, which means that no one inside or outside an organization should be automatically trusted. This approach assumes that all systems and networks are potentially compromised and therefore requires strict controls and continuous monitoring to verify the identity and intentions of all users, devices, and systems that are attempting to access resources on the network. To implement the Kipling Method, an organization would need to establish strong authentication and access controls, implement macro, micro, and nano segmentation, and continuously monitor and analyze network traffic to detect and respond to potential threats.

“When every user, packet, network interface, and device is untrusted, protecting assets (applications and data) becomes simple”34

Who? What? When? Where? Why? How? User Application Time

Limitations Type of Device/Workload Data Classification Content/Data

Group Users 1

UUID Business Hours

System Object_X Internal Threat Protection

Group Users 2

Non-Business Hours

Container_A Restricted SSL Description

IoT Device 1

Virtual Machine_B Highly Restriced URL Filtering

Group Process A

Business Hours

Container 1 Public File System Permissions

Table 2: How to build a policy through the Kipling-Method35

At this stage, we have described the Zero Trust network access. Now let's focus on the datacenter where we have the applications and data.

In the Resource Authorization Decision Point, we have the intermediary decision point where the security policy evaluates the confidence level, or trust score, to decide if the user/device is allowed access. This is typically implemented with the macro-segmentation architectures where organizations have divided the corporate network into smaller, controlled segments with different attributes associated with the Business.

Landing zones help enterprises to deploy, use, and scale application services more securely and dynamically, allowing the growing to adopt workloads over time. This approach is important because here we implement the Application Delivery Control. It’s defined as a delivery controller typically placed in a public cloud or on-premises datacenter between the point of enforcement in the macrosegment (aka. firewall) in the area known as DMZ. Typical technologies are application load balancers, SSL off-load, acceleration services or the Intrusion Prevention System.

Additionally, in this block, we have the micro-segmentation, which focuses only on creating logical network zones to isolate segments according to the risk and data classification. These segments are secured by enabling granular access control and/or threat prevention, whereby users, applications, workloads, and devices are segmented based on logical attributes with the goal to reduce surface attacks.

34 John Kindervag: ‘The Hallmark of Zero Trust Is Simplicity’ – URL: https://deloitte.wsj.com/articles/john-kindervag-the-hallmark-of- zero-trust-is-simplicity-01618513330 35 Zero Trust Implementation and Guiding Principles Briefing by John Kindervag - https://cloudsecurityalliance.org/research/working- groups/zero-trust/

https://deloitte.wsj.com/articles/john-kindervag-the-hallmark-of-zero-trust-is-simplicity-01618513330 https://deloitte.wsj.com/articles/john-kindervag-the-hallmark-of-zero-trust-is-simplicity-01618513330 https://cloudsecurityalliance.org/research/working-groups/zero-trust/ https://cloudsecurityalliance.org/research/working-groups/zero-trust/

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 30 The security settings should be applied to different types of traffic, creating policies that limit network and application flows between workloads to those that are explicitly permitted.

Figure 34: Macro-segmentation, micro-segmentation (workload-to-workload and subnet to subnet) and nano-segmentation

Once the connection has been authenticated and distributed or balanced correctly, we have the next block, called the Application Authorization Point. In the previous blocks we have network devices, however, in this block the decision point is focused on the evaluation of how the user can gain access to the application or how workload A can gain access to workload B. Here we have the nano segments, where segmentation gateways and API access decision points can limit access on a per identity basis to explicitly allow API invocations, with allowance granularity down to the "verb" level.

However, in the Application Authorization Point we need to protect how developers use best practices to protect the code in the applications. According to the Global Cybersecurity Outlook 2022, prepared by the World Economic Forum36, digital transformation is the main driver in improving cyber resilience. However, two main critical problems are rising: Ransomware attacks are increasing in frequency and sophistication, and there are threats to supply chains, partner networks, and ecosystems.

Therefore, DevSecOps Application Development is a set of software development practices that combines software development (Dev), security (Sec), and information technology operations (Ops) to secure the outcome and shorten the development lifecycle. Having a solid DevSecOps, the software features, patches, and fixes can occur more frequently and in an automated fashion. Cyber security is applied at all phases of the software lifecycle and the adoption of DevSecOps applies to application development and production environments equally. This is precisely how we can protect the applications. Finally in the operation we have the Data Authorization Decision Point: Data owners use Data Reference Architecture to apply tagging to data using APIs through orchestrators or using DLP servers. Data Right Management is a set of access control technologies, aligned with data classification, that help to prevent unauthorized access from users (humans or machines), modifying and redistributing data-in-motion, data-at-rest, and data-in-use. The main enforcement for data consists of encryption methods and its key is tied to policies defined by the data owner. This key is tied to the security policy of the data enforcing the least privilege authorization.

36 Global Cybersecurity Outlook 2022 Report – Source: https://www3.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2022.pdf

https://www3.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2022.pdf

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 31 Data or the "value" described by Forrester, is the final step in the user-data service contract, based on the access to the data and applications. Data tagging defines the attributes which determine conditional access that should be aligned to the data classification to facilitate automation. Artificial intelligence is used to assist in the tagging process. In this block, the enterprise should have a mature data classification process with at least four levels: highly restricted, restricted, internal and public. Having explained the data plane, let's discuss how the control plane, the ‘brain’ of Zero Trust, integrates the pillars ‘analytic’ and ‘visibility’ with automation and orchestration.

a) Dynamic Access Control Plane: o Policy Engine & Automation (SOAR): Our Zero-Trust

Architecture will require dynamic policy enforcement and automation. SOAR is the component to address this, working seamlessly with analytics and policy engines, and creating confidence levels or ‘trust scores’. It also automates the delivery of policy to enforcement points (devices, networks, workloads, and data).

b) Automated Policy Deployment: The actions required are automatically deployed by the

engine/orchestrator based on analytics, baselining, and behaviors needing to be implemented at enforcement points.

c) Endpoint Detection and Response (EDR): The tool that provides real-time monitoring and detection of malicious events on endpoints, visualizing the threats in timelines, alerting, and remaining updated when a malicious actor is performing an attack (e.g., ransomware, malware).

d) User Activity Monitoring (UAM): The surveillance of user activity, in the applications, data, and network. A typical example is the analysis of the web browsing activity and how users (humans or machines) are accessing unauthorized or sensitive files.

e) Analysis & Confidence Scoring: The technologies perform continuous assessments of entities, attributes, and configurations, allowing to adapt and risk-optimize the security policies for deployments. This Confidence Scoring can be defined as the trust score in accordance with different levels of analysis. As previously explained, "The major vulnerability is the lack of good identity governance", which is a consequence of weak or low scoring in the conditional access (context). This could lead to a compromise of the system and is therefore one of the most important elements in security operations.

f) Entity Behavior Analysis: The analysis of all the data using machine learning algorithms to model and learn the behavior based on multiple sets of attributes or datasets like the identity, the device, geolocation, and the time defining the confidence level.

g) Data Loss Prevention: The tools and data classification procedures used to detect potential data breaches or ex-filtration transmissions. Also used to prevent it through the surveillance used to detect and block sensitive data-in-use, data-in-motion, and data-at-rest. In the operational model, the analysis of the data and how the compliance of data classification is accomplished is important. Logging the access and the changes in the data (the "value") can also help in the analysis post-mortem through forensic analysis, confidence scoring, and policy automation, if data breaches happen.

h) Logging Utilizing Security Information and Event Management: All activity data is parsed, normalized, aggregated, enriched, and stored in the correlation engine to provide Security Information Management (SIM) and Security Event Management (SEM) capabilities.

i) Activity Auditing: The analysis and review of all logged activities to ensure proper analytics and confidence scoring are aligned with the enterprise compliance objectives and needs. All the enforcement points (users, devices, network, workload, and data) should provide this capability to enable the behavior analysis, while providing the right operational context to do the appropriate access decisions.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 32

Zero Trust and Cloud Transformation Although any organization that is ready to undergo a cloud transformation has a defined set of business goals, we still expect a certain level of alignment with common architectural trends that will help shape the majority of end- state architectures. Three such trends, known as the ‘building blocks of the process’, are referred to in the Gartner "Top Security and Risk Management Trends"37 report: Zero Trust, Cloud Native Security and SASE.

Figure 35: Pillars of the cloud transformation The convergence of these trends is a unified view of a cloud-centric security strategy. This strategy should be considered by every enterprise as a target cloud security architecture and used for their digital transformation journey. Let’s take a look at the contribution of each trend.

Figure 36: Pillars of Cloud Transformation, Sources: Gartner & Forrester

According to the Gartner Hype Cycle for Cloud Security 2021: SASE is close to moving from the peak of inflated expectations to the trough of disillusionment and the expected plateau of productivity (mainstream adoption and market maturity) is around 2-5 years. Consequently, SASE is being implemented by early adopters. In the peak of inflated expectations, technology usage is increasing, however, there may be more hype than proof that the innovation is delivering the results the market wants.

37 Top Security and Risk Management Trends – Source: https://www.gartner.com/doc/reprints?id=1-1YKW4MUN&ct=200310&st=sb

https://www.gartner.com/doc/reprints?id=1-1YKW4MUN&ct=200310&st=sb

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 33 In the following figure we have the mapping of the Zero Trust pillars and the cloud transformation, as well as the harmonization between them.

Figure 37: Zero Trust pillars and cloud transformation.

As ZTNA, CSPM, CWPP move into the slope of enlightenment, early adopters are seeing benefits from the technology and other organizations are seeking to benefit as well. These technologies are projected to deliver real world benefits and mainstream adoption in 2-5 years. Private cloud computing can be a mature technology, soon moving into the plateau of productivity and mainstream adoption in less than 2 years. One technology to follow is identity-based segmentation for applications (CIEM), which is the slope of enlightenment, moving to mainstream adoption at a faster pace, in less than 2 years. Identity-based segmentation according to Gartner, is critical to a Zero Trust security strategy. Although any organizations' rational for cloud transformation is defined by their own very specific business goals, at some level we expect that most will align with a set of common architectural trends and that these will shape the majority of end-state architectures. For more information, you can review the whitepaper related to the Secure Cloud Transformation 2022 journey, let's review the pillars carefully and how are mapped with the Zero-Trust Pillars.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 34

SASE ‒ Secure Access ‒ Service Edge SASE38 means the de-centralization of the datacenter-centric architecture and the moving of users outside of the traditional perimeter. This allows them to consume the internet and corporate services directly from the cloud as SaaS or X'aaS. Security is provided as a service that is built on cloud-native technology and delivered as an OPEX model.

Figure 38: SASE & SSE aligned with the Zero Trust pillars As a general rule, SASE solutions are based on the following pillars:

• Cloud access security broker (CASB) • Zero trust network access (ZTNA) • Firewall as a service (FWaaS) • Secure web gateway (SWG) • Software-Defined Wide Area Network (SD-WAN)

CNAPP ‒ Cloud-Native Applications Protection Platform Cloud-native means building applications for, and in, the cloud on services such as containers and Kubernetes. Cloud-native security is delivered by solutions built in the cloud and designed for the unique security challenges the cloud presents, including CI/CD development processes along with advanced security-operational model – DevSecOps.

Key components:

• CSPM – Cloud Security Posture Management An automatic and continuous check for misconfigurations that can lead to data breaches and leaks allowing the organizations to make necessary changes on a continuous process of cloud security improvements and adaptations to reduce the likelihood of a successful attack.

• CWPP – Cloud Workload Protection Platform It helps to mitigate the impacts of poor security practices during the rapid development cycles common in DevOps keeping keep the applications secure, by providing security for the application and all the associated cloud capabilities. Cloud workloads include the computing (SDC – Software

38 2022 Strategic Roadmap for SASE Convergence – URL: https://www.gartner.com/doc/reprints?id=1-2AFZGMIX&ct=220629&st=sb

https://www.gartner.com/doc/reprints?id=1-2AFZGMIX&ct=220629&st=sb

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 35 Defined Computing), networking (SDN – Software Defined Networking) and storage (SDS – Software Defined Storage) capabilities needed by applications in the cloud.

• CIEM – Cloud Infrastructure Entitlements Management

An automated process of managing user entitlements and privileges in cloud environments. An integral part of an organization's identity, access management, and cloud security posture management (CSPM) infrastructure.

• WAPP - Web Application and API protection Web Application and API Protection (WAAP) are the cloud-based services designed to protect these vulnerable web applications and APIs

• KSPM - Kubernetes Security Posture Management It helps enterprises automate Kubernetes security and compliance to mitigate the security threats posed by human error and oversight across K8s clusters without hampering scalability.

• IaCSec - Infrastructure as a Code Security Infrastructure as a Code deals with automating the process of deploying and configuring virtualized IT resources (SDN, SDC, SDS), while Infrastructure as a Code security is the automation of secure configuration management for these resources.

Figure 39: Cloud Native Application Protection Platform aligned with the Zero Trust pillars

Security Automation and Orchestration

XDR (extended detection and Response) enables the organizations to proactively protect itself against cyber threats by providing unified visibility across multiple attack vectors. For another hand, SOAR (security orchestration, automation, and response) is an stack of compatible software programs (API-Driven) that enable an organization to collect data about security threats and respond to security events without human assistance. Automation

• The process of setting up a single task to run on its own. Automation is a term for technology applications where human input is minimized.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 36 Orchestration

• The process of automating computer system configurations, coordination, and management. Additionally, it simplifies the automated processes by creating building blocks from underlying code, and integrating business intelligence.

Figure 40: Security Operations and Automation/Orchestration aligned with the Zero Trust pillars

SDDC - Software Defined Datacenter The Software-Defined Datacenter (SDDC) concept integrates multiple datacenter infrastructure components where each one is potentially provisioned, operated, and managed through an application programming interface (API). SDC is computer virtualization through the hypervisors, SDN considers the network virtualization merging hardware and software resources and networking functionality into a software-based virtual network and the final, equally important, element, SDS, that includes storage virtualization, integrating a service interface to provision capacity and SLAs (Service Level Agreements) for storage.

Figure 41: Software Defined Datacenter aligned with the Zero Trust pillars

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 37

Zero Trust and Cyber Security Mesh In the previous sections, we described how Zero Trust can be abstracted starting from the business to the technology. However, one of the most typical concerns of enterprises is related to the vast spectrum of solutions in the market, leading to a rise in complexity.

Recently, Gartner defined the Cybersecurity Mesh Architecture (CSMA)39 as a top strategic trend in 2022 to help organizations move toward a more scalable and interoperable approach to security. CSMA aims at simplifying and improving corporate cyber security by providing a framework for discrete security solutions to collaborate on common goals.

Figure 42: Cybersecurity Mesh (Source:Gartner40)

The CSMA and Zero Trust architectures ensure that all data and applications are managed equally and securely, independent of where they are located. Any connection to enterprise data is considered untrusted until the Policy Decision Point (PDP) verifies it under NIST ZTA principles.

CSMA enables stand-alone solutions to work together in complementary ways to improve the overall security posture by standardizing how the tools interconnect. Simply put, it's a collaborative approach to creating cohesion. Therefore, Zero Trust provides the guideline and CSMA provides the technological components to enable the strategy. The cohesion needs fewer resources to work correctly and enhance each action undertaken; consequently, Cybersecurity Mesh and Zero Trust can also be focused on optimizing the CAPEX/OPEX, thus removing unnecessary and costly duplicities. The Check Point Infinity Global Services - Strategic consulting team has found a relationship between Zero-Trust Architecture (ZT) and Cyber Security Mesh Architecture (CSMA) as a growing interest in organizations seeking ways to secure their ever-expanding digital landscape. Zero-Trust (ZT) Principles

• Main Objective: Ensure that every access request to resources is authenticated, authorized, and continuously validated, regardless of origin.

• Focus: Identity, continuous authentication, and authorization.

39 Cyber Security Mesh Architecture – URL: https://www.gartner.com/en/information-technology/glossary/cybersecurity-mesh 40 The Future of Security Architecture: Cybersecurity Mesh Architecture (CSMA) - URL: https://www.gartner.com/doc/4010297

https://www.gartner.com/en/information-technology/glossary/cybersecurity-mesh https://www.gartner.com/doc/4010297

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 38 Cyber Security Mesh Architecture (CSMA) Principles

• Main Objective: Decentralize security measures, ensuring that each node or component in an IT ecosystem can defend itself.

• Focus: Modularity, decentralization, and node-specific security. In coming years, Cybersecurity Mesh will be the next evolution of the Zero Trust model, designed to address the changing landscape of IT infrastructure. With remote work, cloud computing, and the proliferation of IoT devices, Zero Trust principles are essential to controlling and verifying access. But the Cybersecurity Mesh takes it a step further, allowing organizations to create a more flexible and adaptable security posture in the face of a highly distributed and interconnected digital ecosystem.. In other words, “Cybersecurity Mesh builds upon Zero Trust principles to provide a more holistic and responsive approach to cybersecurity in modern, decentralized environments”. As you can see in the Figure 43, the Cybersecurity Mesh aligns the different security controls into the Zero-Trust Pillars, providing a comprehensive and unified approach to protecting your assets. CSMA is designed to provide a scalable, interoperable, and composable framework for various security controls and solutions to interoperate more effectively. The foundational layers define core security goals and functions that various security solutions can collaborate to achieve. We can define the CSMA with the following five foundational layers:

• Distributed Identity Fabric: The layer focused on providing identity and access management

services, which are central to a Zero Trust security policy. Capabilities include decentralized identity management, directory services, identity proofing, entitlement management, and adaptive access.

• Consolidated Policy and Posture Management: Focused on managing and enforcing consistent security policies across various environments and requires translating guidelines for different environments. Solutions at this level convert policies into the rules and configuration settings needed for a particular environment or tool. They can also provide dynamic runtime authorization services.

• Consolidated Dashboards: An array of discrete and disconnected security solutions that impede security operations by forcing context switches between multiple dashboards. This layer provides integrated visibility into an organization's complete security architecture, enabling more efficient detection, investigation, and response to security incidents.

• Security Analytics and Intelligence: A collection of different solutions. This layer focuses on collecting, aggregating, and analyzing security data from various security tools. Based on this data, solutions such as Security Information and Event Management (SIEM) and Security Orchestration,

Figure 43: The Zero-Trust Model and CSMA Components aligned

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 39 Automation and Response (SOAR) tools can analyze potential threats and trigger appropriate threat responses.

• Data Fabric: A composable, flexible, and scalable way to maximize the value of data in an organization as a design concept that serves as an integrated layer (fabric) of data and connects business processes.

Figure 44: Aligning Zero-Trust Model with Cybersecurity Mesh - Reference Architecture – Source Gartner & Check Point Zero-Trust Framework

Infinity-Vision is the unified management platform for Check Point Infinity; the first modern, consolidated cyber security architecture built to prevent today's most sophisticated attacks across networks, cloud, endpoints, mobile and IoT. Powered by the world's largest threat intelligence network, Infinity-Vision centrally manages the Infinity architecture to mitigate attacks effectively in real time, solve security gaps, and reduce the total cost of ownership.

Figure 45: Check Point Infinity CSMA alignment and based on the Gartner Cybersecurity Mesh Architecture.

© November 2023 Check Point Software Technologies Ltd. All rights reserved

THE ULTIMATE JOURNEY TO THE ZERO TRUST FRAMEWORK | 40

Conclusion The Zero-Trust Architecture is highly granular approach where only the minimum possible access (least privilege) is granted to the smallest resource unit in a dynamic way. As we described in this Whitepaper, the “trust” should be considered a major vulnerability and should be constantly reassessed throughout the interaction between the user and the requested resources.

Figure 46: Check Point Infinity Architecture Providing an Zero-Trust Architecture as end to end, the security stretches from the requesting object to the resource requested and detached from preexisting classifications where the terms inside and outside the perimeter are meaningless in the realm of zero-trust.

CONTACT US Worldwide Headquarters | 5 Shlomo Kaplan Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com U.S. Headquarters | 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2117 | Fax: 650-654-4233 | www.checkpoint.com © November 2023 Check Point Software Technologies Ltd. All rights reserved

mailto:info@checkpoint.com http://www.checkpoint.com/

Introduction What is the Zero Trust framework? Zero Trust Maturity Model and implementation Transforming Zero Trust with Check Point Infinity Global Services “Information Security is a journey and not a destination.24F ”

Zero Trust Reference Architecture Zero Trust architecture pillars Zero Trust operational model Zero Trust and Cloud Transformation Zero Trust and Cyber Security Mesh Conclusion


Item Type: pdf