Zero Trust is a framework: what does that mean in concrete terms?

Zero Trust Security: security without trust

How Zero Trust really protects your network

The Zero Trust Security model is based on the principle of not automatically trusting either internal or external users. The aim is to minimize risks, protect data and at the same time prevent internal and external threats. Especially in MPLS or SD-WAN environments, Zero Trust offers a crucial security architecture for modern cloud infrastructures.

In a nutshell:

  • Constant authentication: Every access is continuously checked, regardless of the user’s location.
  • Detailed access control: Authorization takes place at application level, not at network level.
  • Integration of modern security services: combination of VPN, firewall, CASB and ZTNA.
  • Transparent monitoring: Every action is logged and analyzed in a traceable manner.
  • Cloud security: Protection of SaaS and public cloud applications without compromising performance.

The solution: Zero trust replaces one-time network access with continuous checking of every single action. Distributed security functions grow into one instance, which lowers complexity and relieves internal resources.

What this article covers: What zero trust means in day-to-day terms, explained through the image of an office building with a reception desk and a personal security guard, which building blocks belong to it, and how to tell that the first step is due in your company.

The question: Do you know what a user can do inside your network once they are in?









What is the zero trust security model?

The Zero Trust Security model is a security concept based on the principle of not trusting anything or anyone inside or outside a network. The aim is to reduce the security risk in a network and its applications to a minimum and at the same time exclude both external and internal threats.

How do I move in an MPLS/SD-WAN without zero trust?

Imagine your network (MPLS/SD-WAN) as a business building with many areas and functions: the reception is your firewall that checks who is allowed in, comparable to a doorman. As an employee, you have an access card with defined rights. You present the card and gain access to the building, in other words the entire network, regardless of whether you are on site, in your home office or on the move.

It also doesn’t matter whether you have been authenticated via MFA or not. Once you have access, you can move freely around the network, according to your authorizations. For example, you can delete data, create new data or communicate with colleagues. Perhaps you order something in the canteen, this corresponds to actions with budget approval, and when you are finished, you leave the network, just like when you leave the building.

What is the difference with zero trust?

In the Zero Trust model, you have a personal security guard at your side after the firewall. It accompanies you through the entire network, into every system, every file, every application. At every step, it checks whether you are allowed to carry out the respective action and assesses whether your input is secure and permitted, in both directions.

The guard analyzes whether the communication partner is trustworthy in terms of company guidelines. Every file, every level is checked, access is only granted if you have valid authorization, and everything is logged seamlessly until you leave the network again.

Why is this so important and valuable?

In the course of constant digitalization, more and more services are being outsourced to the cloud. You are faced with the challenge of ensuring that your systems work in perfect harmony with one another. This is precisely where the strength of a partner becomes apparent: the extent to which their integrations and services match your profile. We are increasingly seeing companies undergoing a transformation at application level to the cloud (SaaS, public-private cloud) as well as a transformation in the WAN area, away from rigid closed networks to SD-WAN and thus also to the cloud.

Increased attention is being paid here to investing sensibly in the hardware components used, or to reducing these costs where possible, and to connecting newer technologies to security instances. Specifically, this involves the realignment of firewalls, VPN connectors and load balancers, but also services at application level for anti-virus, sandbox, SSL, URL filtering and more.

In addition, and not just since COVID, a sustainable strategy for integrating home office workplaces is needed, which is a challenge to manage and integrate on the one hand and to ensure that the security guidelines are adhered to, at all times, in all places, and can be presented transparently on the other.

Which building blocks are available?

Zscaler Internet Access:

  • Connects the WAN (Internet) securely to SaaS applications and the Internet
  • Included are: Secure Web Gateway, Cloud Access Security Broker (CASB), and Data Loss Prevention

Zscaler Private Access:

  • Connects authorized users to the internal network and shared applications and supports Zero Trust Network Access (ZTNA)


How SAVECALL supports your zero trust rollout

We support you in choosing the right components. SAVECALL advises independently of vendors and carriers and first checks which applications, sites and compliance requirements need to be covered. From that we derive a roadmap that reaches from the first step at identity and authentication through to a co-managed SASE model. We then collect offers from a network of more than 80 partners, negotiate the terms and support rollout and operation. You keep one point of contact for network and security.

Conclusion

With zero trust, you reduce the complexity of connecting a wide variety of applications and increase their security at the same time. You combine solutions that are currently distributed across several levels into a single instance and thus relieve your internal resources. Compared to many other security solutions, the use of zero trust increases security standards by also monitoring and logging internal applications and processes.

Frank Frommknecht, Key Account Consultant at SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has supported companies for more than 20 years in selecting and optimising their connectivity solutions. His focus: making complex telecommunications understandable from the customer perspective and finding the right solution strategically.

Sources

  • Forrester Research, John Kindervag, origin of the zero trust model, 2010
  • NIST, Special Publication 800-207: Zero Trust Architecture, 2020
  • BSI, The State of IT Security in Germany, annual report
  • Zscaler, product documentation on Internet Access and Private Access
  • SAVECALL, Zero Trust and SASE

Zero Trust: questions and answers

Frequently asked questions about the zero trust framework

What is the zero trust security model?

The zero trust security model is a security concept based on the principle of not trusting anything or anyone inside or outside a network. The aim is to reduce the security risk in a network and its applications to a minimum and at the same time exclude both external and internal threats. Instead of one-time access to the entire network, every single action is checked, logged and only released when valid authorization exists.

Why is zero trust a framework and not a product?

Zero trust describes a principle, not a single piece of software. It is implemented through the interplay of several building blocks: identity verification, access control at application level, logging and cloud security services. Zero trust therefore cannot be bought, only built up step by step. Companies combine components such as VPN replacement, firewall functions, CASB and ZTNA into an architecture that fits their applications and sites.

How does zero trust differ from a classic firewall?

A classic firewall checks at the network entrance who is allowed in. After that, the user moves largely freely within the network. Zero trust, by contrast, checks at every step whether the specific action is permitted and assesses communication in both directions. The difference lies not in the technology at the perimeter but in the fact that control travels with the user instead of standing only at the edge.

What does zero trust mean for MPLS and SD-WAN environments?

In classic MPLS networks, everything internal was considered trustworthy. With applications moving to the cloud and the switch to SD-WAN, that assumption loses its foundation. Zero trust adds a security layer to the SD-WAN that applies regardless of location, in the office, at home and on the move. Network and security are then planned together instead of being procured one after the other.

Which building blocks belong to a zero trust architecture?

Typical building blocks are secure internet access with a secure web gateway, cloud access security broker and data loss prevention, plus access to internal applications via zero trust network access. Identity verification with multi-factor authentication and continuous logging complete the picture. Vendors such as Zscaler bundle several of these functions in one platform. Which combination makes sense depends on applications, sites and existing licences.

How does SAVECALL support the introduction of zero trust?

SAVECALL advises independently of vendors and carriers and supports you in choosing the right components. We first check which applications, sites and compliance requirements need to be covered and derive a roadmap from that. We then compare offers from a network of more than 80 partners, negotiate terms and support rollout and operation. You keep one point of contact for network and security.

Articles that may also interest you

Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

What drives you forward – & what drives

Book a free expert consultation