CyberzSOC

Publication detail
← Back to advisories & guidance

CSI: Advancing Zero Trust Maturity Throughout the Network and Environment Pillar ↗ source

March 5, 2024 NSA Guidance
Co-sealed by: CISA, NSA, NSM

Summary

The Zero Trust network and environment pillar curtails adversarial lateral movement by employing controls and capabilities to logically and physically segment, isolate, and control access (on-premises and off-premises) through granular policy restrictions. The network and environment pillar works in concert with the other Zero Trust pillars as part of a holistic Zero Trust security model that assumes adversary breaches occur inside the network, and so limits, verifies, and monitors activities throughout the The concepts introduced in this cybersecurity information sheet provide guidance on enhancing existing network security controls to limit the potential impact of a compromise through data flow mapping, macro and micro segmentation, and software defined networking. These capabilities enable host isolation, network segmentation, enforcement of encryption, and enterprise visibility. As organizations mature their internal network control, they greatly improve their defense-in-depth posture and, consequently, can better contain, detect, and isolate network intrusions. U/OO/125052-24 | PP-24-0689 | MAR 2024 Ver. 1.0 According to public reports, an American retail corporation experienced a significant data breach in 2013 due to a lack of network segmentation.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.