Cloud 101
Circle
Events
Blog

Download Publication

Earning Trust in the 21st Century
Earning Trust in the 21st Century

Earning Trust in the 21st Century

Release Date: 01/26/2021

In today’s interconnected and technology reliant world, the expectation of trust and need to trust is growing. Today’s trust-based solutions may become non-viable in the future. As use of the cloud grows, we are experiencing a shift in resource allocation from on-premise to off-premise systems. As systems move to cloud-hosted environments, the loss of control over the access network becomes a concern. Today’s trust-based solutions typically start at the network level. If a user has access to a network, they are typically trusted to have access to some or all of the resources, data, and systems on that network.

But, when networks are unknown and untrusted, how is trust acquired? Zero Trust architectures seek to provide access control techniques that assume the network is not trustworthy. One of the approaches suggested by industry is the use of trust scores. Like a credit score, a cyber trust score could be used to assess the risk potential associated with allowing any given user access to systems and information. But how would a trust score be calculated? Current approaches smack of a violation of privacy where the right to gain access is issued only by agreeing to be monitored.

This paper addresses the technical, social, policy, and regulatory issues associated with creating trust frameworks in a Zero Trust world. Industry and government are called to solve issues in ways that continue to protect the right to a users’ privacy.

Download this Resource

Prefer to access this resource without an account? Download it now.

Acknowledgements

Juanita Koilpillai
Juanita Koilpillai
Founder & CEO of Waverley Labs

Juanita Koilpillai

Founder & CEO of Waverley Labs

Juanita Koilpillai is Founder and CEO of Waverley Labs, a pioneer in software defined perimeters (SDP) and digital risk reduction solutions. She has 30 years’ experience researching and developing systems in computer security, network management and real-time distributed software. She leads the open source software-defined perimeter (SDP) effort for ‘black’ apps in the cloud with the Cloud Security Alliance and is an active contributor to N...

Read more

Anil Karmel
Anil Karmel
Co-founder and CEO, RegScale

Anil Karmel

Co-founder and CEO, RegScale

Anil Karmel serves as the co-founder and CEO of RegScale designed to bring the principles of DevOps to Compliance (Regulatory Operations: RegOps). Formerly, Anil served as the National Nuclear Security Administration's (NNSA) Deputy Chief Technology Officer. Karmel began his government career as a Technical Staff Member of Los Alamos National Laboratory (LANL) and was responsible for inventing their cloud and collaboration technologies Karm...

Read more

Frank Guanco
Frank Guanco
Research Program Manager, CSA

Frank Guanco

Research Program Manager, CSA

This person does not have a biography listed with CSA.

Dan Hiestand Headshot Missing
Dan Hiestand

Dan Hiestand

This person does not have a biography listed with CSA.

Todd Edison
Todd Edison
Chapter Relations Manager, CSA

Todd Edison

Chapter Relations Manager, CSA

This person does not have a biography listed with CSA.

Dr. Mari Spina
Dr. Mari Spina
Principal Cybersecurity Engineer/ Cloud Security Capability Leader at MITRE

Dr. Mari Spina

Principal Cybersecurity Engineer/ Cloud Security Capability Leader at MITRE

Dr. Spina joined MITRE in 2014 and has been supporting a multitude of MITRE Federal sponsors including DHS, DoD and the IC in the area of Cloud Security. At MITRE, she is a Principle Cybersecurity Engineer, leads the Cloud Security Capability Area, and teaches Cloud Security for the MITRE Institute. She has also taught many Information Technology courses for the George Washington University schools of engineering and business. Before joini...

Read more

Simran Sakraney Headshot Missing
Simran Sakraney

Simran Sakraney

This person does not have a biography listed with CSA.

Justin Agostine Headshot Missing
Justin Agostine

Justin Agostine

This person does not have a biography listed with CSA.

Al Aresenault Headshot Missing
Al Aresenault

Al Aresenault

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.