Cloud 101CircleEventsBlog
Register for CSA’s free Virtual Cloud Trust Summit to tackle enterprise challenges in cloud assurance.

Download Publication

Earning Trust in the 21st Century
Earning Trust in the 21st Century

Earning Trust in the 21st Century

Release Date: 01/26/2021

In today’s interconnected and technology reliant world, the expectation of trust and need to trust is growing. Today’s trust-based solutions may become non-viable in the future. As use of the cloud grows, we are experiencing a shift in resource allocation from on-premise to off-premise systems. As systems move to cloud-hosted environments, the loss of control over the access network becomes a concern. Today’s trust-based solutions typically start at the network level. If a user has access to a network, they are typically trusted to have access to some or all of the resources, data, and systems on that network.

But, when networks are unknown and untrusted, how is trust acquired? Zero Trust architectures seek to provide access control techniques that assume the network is not trustworthy. One of the approaches suggested by industry is the use of trust scores. Like a credit score, a cyber trust score could be used to assess the risk potential associated with allowing any given user access to systems and information. But how would a trust score be calculated? Current approaches smack of a violation of privacy where the right to gain access is issued only by agreeing to be monitored.

This paper addresses the technical, social, policy, and regulatory issues associated with creating trust frameworks in a Zero Trust world. Industry and government are called to solve issues in ways that continue to protect the right to a users’ privacy.

Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
IoT Controls Matrix v3
IoT Controls Matrix v3
Guide to the IoT Controls Matrix v3
Guide to the IoT Controls Matrix v3
Disaster Recovery as a Service
Disaster Recovery as a Service
Navigating Your Cloud Journey in 2024: Key Resources from the Cloud Security Alliance
Navigating Your Cloud Journey in 2024: Key Resources from the Cloud...
Published: 04/05/2024
Runtime is the Way
Runtime is the Way
Published: 04/04/2024
10 Essential Identity and Access Management (IAM) Terms
10 Essential Identity and Access Management (IAM) Terms
Published: 03/30/2024
Security Compliance for Cloud Services
Security Compliance for Cloud Services
Published: 03/29/2024

Acknowledgements

Juanita Koilpillai
Juanita Koilpillai
Pioneer of Software Defined Perimeter

Juanita Koilpillai

Pioneer of Software Defined Perimeter

Juanita Koilpillai was Founder and CEO of Waverley Labs, a pioneer in software defined perimeters (SDP) and digital risk reduction solutions. She had 30 years’ experience researching and developing systems in computer security, network management and real-time distributed software. She led the open source software-defined perimeter (SDP) effort for ‘black’ apps in the cl...

Read more

Anil Karmel
Anil Karmel
CEO, C2 Labs

Anil Karmel

CEO, C2 Labs

Anil Karmel is the Co-Founder and CEO of RegScale, which helps organizations start and stay compliant via the world's first real-time GRC platform. Formerly, Anil served as the National Nuclear Security Administration's (NNSA) Deputy Chief Technology Officer. Karmel began his government career as a Technical Staff Member of Los Alamos National Laboratory (LANL) and was responsible for inventing their cloud and collaboration technologies Kar...

Read more

Frank Guanco
Frank Guanco
Research Program Manager, CSA

Frank Guanco

Research Program Manager, CSA

This person does not have a biography listed with CSA.

Dan Hiestand Headshot Missing
Dan Hiestand

Dan Hiestand

This person does not have a biography listed with CSA.

Dr. Mari Spina
Dr. Mari Spina
Sr. Principal Cybersecurity Engineer / Cloud Security Capability Leader at MITRE

Dr. Mari Spina

Sr. Principal Cybersecurity Engineer / Cloud Security Capability Leader at MITRE

Dr. Spina joined MITRE in 2014 and has been supporting a multitude of MITRE Federal sponsors including DHS, DoD and the IC in the area of Cloud Security. At MITRE, she is a Principle Cybersecurity Engineer, leads the Cloud Security Capability Area, and teaches Cloud Security for the MITRE Institute. She has also taught many Information Technology courses for the George Washington University schools of engineering and business. Before joini...

Read more

Simran Sakraney Headshot Missing
Simran Sakraney

Simran Sakraney

This person does not have a biography listed with CSA.

Justin Agostine Headshot Missing
Justin Agostine

Justin Agostine

This person does not have a biography listed with CSA.

Al Aresenault Headshot Missing
Al Aresenault

Al Aresenault

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.

Related Certificates & Training