Zero Trust

The zero-trust concept is that organizations should not trust without first verifying access.

2 slides · 1 min read · Domain 3

Slide 1

Zero trust is the security concept that organizations should not trust anything inside or outside their network without first verifying access to the system.

Outside the network, exploits could occur, and security controls should be implemented to minimize the threats such as firewalls, access controls, and virus protection.

Inside the network, security precautions should be taken to reduce an insider threat. An insider threat is when an insider will use their authorized access, wittingly or unwittingly, to do harm to the security of organizational operations and assets, individuals, other organizations, and the nation. This threat can include damage through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of organizational resources or capabilities. (CNSSI 4009, adapted). Some of the types of controls that can be implemented to minimize an insider threat include security awareness training, background checks, and access controls.

Test this domain