🔧 ProgrammierungWebKit Features for Safari 27.0(17.09.2026 um 13:30 Uhr)
🔧 ProgrammierungWebKit Features for Safari 27.0(17.09.2026 um 13:30 Uhr)
📰 IT Security Nachrichten 🕛 vor 4 Jahren 8 Min Lesezeit SECURITY-FEED
0

What is the NIST Zero Trust Architecture?

↗ Quelle (twingate.com)
🗣️ Stimme:
📑 Inhaltsübersicht

Two years ago, the National Institute of Standards and Technologies (NIST) issued a report defining a new paradigm for secure network access. The NIST Zero Trust Architecture outlines how organizations can improve security by replacing legacy technologies such as virtual private networks (VPN). This 59-page document comprehensively explores the principles and implications of is a modern approach to secure network access that avoids the security weaknesses and inefficiencies of legacy technologies such as virtual private networks or remote desktop protocol (RDP). Designed for today’s distributed network architectures, Zero Trust solutions let organizations manage all users, devices, and resources within a single system. Zero Trust delivers seamless access to users no matter where they are while keeping resources secure amid the growing sophistication of today’s cybercriminals.

Legacy technologies are unsecure

For decades, organizations have used a “secure perimeter” framework to protect sensitive networked resources. Security administrators focused on locking down private networks to prevent access from outside the organization’s walls. Employees used managed desktops on this private network to access the resources they needed.

VPN, RDP, and other specialized technologies let a few employees access the network remotely. Gateway devices positioned outside the network provided a portal through the firewall so these users could access the network.

What worked decades ago no longer works today. Secure perimeter technologies have become vectors for cyberattacks. Gateways publish their presence to the public internet. By constantly scanning every gateway, cybercriminals can spot an unpatched device before administrators know an update is available. In addition, users’ devices and credentials are vulnerable to malware and social engineering attacks. Since VPN gateways provide access to networks rather than to specific resources, these vulnerabilities create significant risks to an organization’s security.

Legacy technologies are inefficient

Legacy approaches also make an organization’s networks inefficient. As work-from-home policies during the pandemic made clear, gateways are bandwidth chokepoints for all remote traffic. In addition, the private network must handle traffic flowing between remote users and cloud-based resources. Besides degrading the private network’s bandwidth, this backhaul adds latency to users’ connections.

In addition to the performance impact, legacy technologies such as VPN are more difficult and expensive to manage. Changes to access policies can require changes in the infrastructure and vice versa. Upgrading or replacing a VPN gateway can disrupt the organization.

What are the NIST Zero Trust definitions?

Zero Trust was introduced as an academic concept in the 1990s. National security planners have worked with similar concepts for decades. A few years after Forrester analysts popularized Zero Trust in 2010, Google began developing its in-house Zero Trust network architecture.

In 2020, the give users the least amount of access needed to do their work within the context of the access request. These permissions are ephemeral, disappearing when the session ends, times out, or when any trust factor changes.

Why are organizations interested in Zero Trust?

Zero Trust does not have the security and efficiency weaknesses of traditional secure perimeter technologies. In an increasingly distributed networking and cybersecurity environment, Zero Trust makes organizations more secure while improving productivity and network performance.

  • Shrinking the attack surface - Replacing publicly-visible gateways with invisible Zero Trust proxies hides distributed networks from attackers.
  • Preventing access policies stop hackers from roaming through networks. Administrators can identify and mitigate attacks faster, reducing the blast radius of successful attacks.
  • Simplifying granular control - Zero Trust lets organizations control access for each resource, each role, and each context through simple administrative tools.
  • Unifying all users and resources - Administrators can apply common security policies for all users and resources, including third-party resources.
  • Reducing network costs - Decoupling to adopt Zero Trust. Within 60 days, every agency had to

    … develop a plan to implement Zero Trust Architecture, which shall incorporate, as appropriate, the migration steps that the National Institute of Standards and Technology (NIST) within the Department of Commerce has outlined in standards and guidance, describe any such steps that have already been completed, identify activities that will have the most immediate security impact, and include a schedule to implement them.

    To help agencies implement these plans by Fiscal 2024, the Executive Order directed the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) to:

    …modernize its current cybersecurity programs, services, and capabilities to be fully functional with cloud-computing environments with Zero Trust Architecture [and] develop security principles governing Cloud Service Providers (CSPs) for incorporation into agency modernization efforts.

    One month later, CISA published a draft version of its Zero Trust Maturity Model. This roadmap is meant to guide federal agencies as they migrate their networks to Zero Trust.

    Twingate’s vision for the future of Zero Trust

    Zero Trust is becoming part of every organization’s security roadmap, from an academic thesis to a solution for modern cyber threats. Twingate has helped large and small organizations begin their Zero Trust journeys. Our scalable, software-based solutions run parallel with legacy architectures, letting security administrators implement Zero Trust where it is most impactful while phasing in our secure access solution over time.

    In our 2022 Zero Trust Outlook Report, we take a by-the-numbers approach to documenting the current state of Zero Trust. We explain why organizations in every sector are turning to this modern security model to support today’s distributed networks. for individuals and small teams.

    Vollständiges Original-Advisory
    Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf twingate.com.
    ↗ Original-Artikel auf twingate.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
The amount of e-waste caused by AI is underestimated: we can’t only include the servers
1 Quelle
Crusoe raises $3.9B to build massive data centers and small modular “AI factories”
1 Quelle
GitHub Release: openai/codex vrust-v0.156.0-alpha.1 (18.09.2026)
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten What is the NIST Zero Trust Architecture?

Thematisch verwandte Begriffe: What, NIST, Zero, Trust · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...