Categories: News

Pentagon to open the Zero Trust Office, next month

The US Department of Defense will be investing more into cybersecurity measures with the opening of its new Zero Trust office next month. David McKeown, Pentagon CISO, said that the office will report to the CIO until a senior executive is named.

SolarWinds campaign speeds up Zero Trust Office

With leadership buy-in, the authorities adopted the Zero Trust, leading to the opening of the new facility. This decision is partly a response to the SolarWinds campaign in which Russian spies compromised nine federal government departments.

McKeown explained that the agency fought to solve this problem faster. Thus, the management will “rationalize all network environments out there.” Also, it will “prioritize and set each one of them on a path of Zero Trust over the coming five, six, seven years,” he explained.

The White House issued an executive order in May. This requires agencies provide a plan for Zero Trust architecture within 60 days. The plan should come with best practice migration steps from NIST. Also it should mention the steps that the agencies took. Moreover, the plan would have to identify activities that will have the most immediate security impact. Of course, there should also be a schedule for these.

Network segmentation would be the key

In the face of growing cybersecurity threats, companies must adopt a Zero Trust approach to their networks. This way, once an attack has been detected, the intruder cannot move laterally through the network undetected. Felipe Duarte, senior researcher at Appgate, said that there is only one chance to detect intruders. This would be “by segmenting the networks and assuming all connections can be compromised.

He also added that authorities should implement the Zero Trust “in the core infrastructure.” Thus, they can profile any device that would try to connect in the network. Also, a key measure would be multi-factor authentication. Thus, the potential attackers could not compromise credentials. Moreover, they should segment networks and provide access only to what each user or system has to do.

Laurentiu Titei

Recent Posts

How to Use a VPN in Incognito Mode: Complete Guide

It may come as a shock: Google was ordered to destroy billions of users' data…

2 hours ago

How to Block Third-Party Cookies in a Browser

This website uses cookies” pop-up often appears when you visit a website on your browser.…

1 day ago

How to Install VPN on Smart TV: Step by Step Guide

Almost every smart TV is packed up with several pre-installed apps, but there are also…

2 days ago

How to Configure a Virtual Directory on Windows IIS Server

Understanding a virtual directory and how to create it on a Windows IIS (Internet Information…

3 days ago

Best Wise Alternative Apps

Wise, a financial technology company, specializes in cross-border money transfers, currency conversion, and international account…

4 days ago

Best Payment Gateways for Safe Payments

With ever-growing digital payments, business owners often find themselves confused about which payment gateways to…

5 days ago