Zero Trust Architecture: NIST vs. MITRE ATTACK

Zero Trust Architecture using threat-informed defence: NIST vs. ATT&CK.

I know Zero Trust (ZT) is an often overused and sensationalised buzzword that gets thrown around a lot these days. Still, criticism aside, the underlying concepts and ideas behind zero trust are solid and will dramatically improve your security posture IF you implement them.

I’ve been in several projects in the past where zero trust has been a major focus, and some of the big question(s) that come up early on are things like:

How do we start?

Where do we start?

How do we scope zero trust?

How many controls do we need to implement?” …The answer is always 23.

These questions have been in the back of my mind for a while now, and I figured it would be a good idea to try to present the answers on a single page that can be used as a reference for future initiatives.

I landed on using NIST as a point of reference for control selection, given they have published the industry standard for a Zero Trust Architecture; see this link for more on NIST SP 800-207 (https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf)

Taking things a step further, I added a threat-informed defence aspect to this project by introducing the MITRE ATT&CK techniques that map to each ZT pillar. This shows that numerous attack techniques can still be attempted within a zero-trust framework, albeit with increased complexity.

A Threat-informed Zero Trust Architecture

If there’s one key takeaway from this visual, I want it to be this: 

When applied in-depth, Zero Trust will greatly reduce your attack surface and strengthen your security posture, but it isn’t the magic bullet that will solve your need for active threat defence or stop you from being attacked. Always master the fundamentals first!

  • Continuously assess your threat landscape & identify high-value assets.

  • Maintain, update and test your incident response plan.

  • Patch, patch, and more patching. Maintain an up-to-date patch management lifecycle.

  • Apply anti-malware/anti-virus solutions.

  • Implement strong access management controls.

  • Emphasise security training and awareness.

  • Securely encrypt sensitive data and maintain/test backup strategy.

Previous
Previous

Threat-informed Business Security Architecture

Next
Next

Evolving Security Operations - The Paradigm Shift We All Need To Make