{"id":3487,"date":"2022-11-21T10:14:42","date_gmt":"2022-11-21T15:14:42","guid":{"rendered":"https:\/\/www.indigoconsulting.ca\/?p=3487"},"modified":"2022-11-21T12:08:33","modified_gmt":"2022-11-21T17:08:33","slug":"zero-trust-cybersecurity-checklist","status":"publish","type":"post","link":"https:\/\/www.indigoconsulting.ca\/fr\/blog\/zero-trust-cybersecurity-checklist\/","title":{"rendered":"Embracing zero trust cybersecurity: A checklist to get you started"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"3487\" class=\"elementor elementor-3487\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7e09750b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7e09750b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-71a723fa\" data-id=\"71a723fa\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-62aad444 elementor-widget elementor-widget-text-editor\" data-id=\"62aad444\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignright wp-image-3489\" src=\"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-300x200.jpg\" alt=\"\" width=\"500\" height=\"334\" srcset=\"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-300x200.jpg 300w, https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-1024x683.jpg 1024w, https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-768x513.jpg 768w, https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-1536x1025.jpg 1536w, https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-2048x1367.jpg 2048w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p><p><span style=\"font-weight: 400;\">The early days of network security were defined by static, nigh-immutable perimeters. Every user and asset inside that perimeter was treated with implicit trust. This worked well enough in a world where in-office work was the norm and cybercriminals operated largely independently of one another. <\/span><\/p><p><span style=\"font-weight: 400;\">How things have changed.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">We now live in a world defined by distributed networks, complex digital supply chains, and remote work. Threat actors are considerably more organized and advanced, particularly with the <\/span><a href=\"https:\/\/cybernews.com\/security\/crimeware-as-a-service-model-is-sweeping-over-the-cybercrime-world\/\"><span style=\"font-weight: 400;\">rise of Cybercrime-as-a-Service<\/span><\/a><span style=\"font-weight: 400;\">. Threats are not only more sophisticated, they&#8217;re also more numerous and dynamic \u2014 <\/span><a href=\"https:\/\/dataprot.net\/statistics\/malware-statistics\/\"><span style=\"font-weight: 400;\">560,000 new pieces of malware are detected <\/span><i><span style=\"font-weight: 400;\">each day.<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">\u00a0 <\/span><\/i><span style=\"font-weight: 400;\">Add to that the availability of contextual information for devices, location, behaviors, and other metrics, and it\u2019s clear why companies are heavily investing in digital security.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">Legacy antivirus software and perimeter-based network security simply cannot keep up. Many organizations have taken to deploying a new point solution to address each new threat or risk. This has led to bloated, unsustainable security stacks which put added strain on security teams that are already struggling to keep up.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">Today&#8217;s business landscape demands a new approach to security, one built on Zero Trust.\u00a0<\/span><\/p><p><a href=\"https:\/\/www.darkreading.com\/perimeter\/forrester-pushes-zero-trust-model-for-security\"><span style=\"font-weight: 400;\">First introduced in 2010<\/span><\/a><span style=\"font-weight: 400;\"> by analyst Forrester Research, Zero Trust is a security model built on a simple concept \u2014 <\/span><i><span style=\"font-weight: 400;\">trust no one. <\/span><\/i><span style=\"font-weight: 400;\">Under a Zero Trust framework, everyone, no matter their position in an organization&#8217;s hierarchy, must submit to authentication, authorization, and continuous validation. Per Forrester, <\/span><a href=\"https:\/\/www.forrester.com\/blogs\/the-definition-of-modern-zero-trust\/\"><span style=\"font-weight: 400;\">this approach is based around the following principles<\/span><\/a><span style=\"font-weight: 400;\">:\u00a0<\/span><\/p><ul><li><span style=\"color: #003a5d;\"><b>Treat all entities as untrusted by default<\/b><\/span><span style=\"font-weight: 400;\"><strong><span style=\"color: #003a5d;\">.<\/span><\/strong> Deny all unauthenticated access to systems, data, and applications.\u00a0<\/span><\/li><li><span style=\"color: #003a5d;\"><b>Enforce Least Privilege<\/b><\/span><span style=\"font-weight: 400;\"><strong><span style=\"color: #003a5d;\">.<\/span><\/strong> Each user must have access <\/span><i><span style=\"font-weight: 400;\">only <\/span><\/i><span style=\"font-weight: 400;\">to what they absolutely need in order to do their job.\u00a0<\/span><\/li><li><span style=\"color: #003a5d;\"><b>Implement comprehensive security monitoring. <\/b><\/span><span style=\"font-weight: 400;\">For security and enforcement purposes, maintain full visibility into your entire ecosystem, including critical assets.\u00a0<\/span><\/li><li><b><span style=\"color: #003a5d;\">Incorporate risk-based verification.<\/span>\u00a0 <\/b><span style=\"font-weight: 400;\">The likelier that a particular access request could lead to a cyber incident, the more stringent your authentication processes must be.\u00a0<\/span><\/li><li><span style=\"color: #003a5d;\"><b>Ensure continuous authentication. <\/b><\/span><span style=\"font-weight: 400;\">Even once a user is verified and granted access, continue monitoring their activity to verify their identity and check for suspicious behavior.\u00a0<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">It&#8217;s important to understand that Zero Trust is not a static security model. It is an ongoing process, one which requires regular revisits and revisions. Successful adoption of Zero Trust therefore requires:\u00a0<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Organization-wide alignment.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Leadership buy-in.\u00a0<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The right processes and policies.\u00a0<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The right technology.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The right mindset.<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">The above components cannot be addressed in isolation, but instead must be treated as part of a unified whole, with each supporting the others. Given the level of complexity this entails, it&#8217;s often difficult to know where to start. That&#8217;s why below, we&#8217;ve compiled a comprehensive checklist of every component involved in Zero Trust adoption.\u00a0<\/span><\/p><h2><strong><span style=\"color: #003a5d;\">Mindset<\/span><\/strong><\/h2><p><i><span style=\"font-weight: 400;\">Zero Trust is a complete departure from traditional perimeter-based security. Before you can define the processes and adopt the technologies necessary to support it, you must first establish a culture that embraces it. You need the right mindset, lest everything else fall flat.\u00a0<\/span><\/i><b><\/b><\/p><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Build for usability.<\/b><\/span><span style=\"font-weight: 400;\"> Security and usability now go hand-in-hand. <\/span><b>\u00a0<\/b><span style=\"font-weight: 400;\">The days when an organization could afford to ignore the user experience of its security tools are well behind us.\u00a0<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Trust no one. <\/b><\/span><span style=\"font-weight: 400;\">It doesn&#8217;t matter if someone is your Chief Information Security Officer or an intern in the mailroom. From a Zero Trust standpoint, neither user can be trusted without verification.\u00a0\u00a0<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Stop believing you&#8217;re safe.<\/b><\/span><span style=\"font-weight: 400;\"> Your organization is not too small to be breached. On the contrary, <\/span><a href=\"https:\/\/www.forbes.com\/sites\/edwardsegal\/2022\/03\/30\/cyber-criminals\/?sh=338b33af52ae\"><span style=\"font-weight: 400;\">small businesses are targeted more frequently by threat actors than large organizations<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Look at the user, not the device. <\/b><\/span><span style=\"font-weight: 400;\">Many business users now own multiple devices, all of which they use in the workplace. Authenticating each individual device makes it significantly more difficult to determine when a user has been compromised. Identity-based authentication does not suffer from this shortcoming.\u00a0<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Accept that the perimeter is gone. <\/b><\/span><span style=\"font-weight: 400;\">Firewalls, virtual private networks, and perimeter-focused security solutions are no longer sufficient. Your ecosystem now extends far beyond the network&#8217;s edge, and your perimeter can no longer fully protect you.<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Understand the value of cybersecurity. <\/b><\/span><span style=\"font-weight: 400;\">If you&#8217;re having trouble defining the ROI of a security solution, consider the reputational damage, data loss, productivity loss, and regulatory fines that might ensue if your organization were breached.\u00a0<\/span><\/li><\/ul><h2><span style=\"color: #003a5d;\"><strong>Processes &amp; Policies<\/strong><\/span><\/h2><p><i><span style=\"font-weight: 400;\">Wielded by unskilled hands, even the most powerful weapon is underwhelming. Similarly, even the most formidable security architecture on the market will fall short if no one understands how to apply it. That&#8217;s why in many ways, process and policy documentation represents the bedrock of Zero Trust.<\/span><\/i><b><\/b><\/p><ul><li aria-level=\"1\"><b><span style=\"color: #003a5d;\">Industry standards.<\/span> <\/b><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-207\/final\"><span style=\"font-weight: 400;\">NIST 800-207<\/span><\/a><span style=\"font-weight: 400;\"> is the most widely-accepted standard for Zero Trust, as it&#8217;s not only comprehensive, but also vendor- and industry-neutral. Other Zero Trust Models include <\/span><a href=\"https:\/\/www.cisa.gov\/zero-trust-maturity-model\"><span style=\"font-weight: 400;\">CISA&#8217;s Zero Trust Maturity Model<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/zero-trust\"><span style=\"font-weight: 400;\">Microsoft&#8217;s Evolving Zero Trust Model<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>User. <\/b><\/span><span style=\"font-weight: 400;\">Every user in your organization should be defined based on:\u00a0<\/span><ul><li><span style=\"font-weight: 400;\">Department.\u00a0<\/span><\/li><li><span style=\"font-weight: 400;\">Roles and responsibilities.<\/span><\/li><li><span style=\"font-weight: 400;\">Level of authority<\/span><\/li><li><span style=\"font-weight: 400;\">Required access permissions\/privileges.\u00a0<\/span><\/li><\/ul><\/li><li aria-level=\"1\"><b><span style=\"color: #003a5d;\">Compliance management.<\/span> <\/b><span style=\"font-weight: 400;\">To ensure adherence with both industry rules and your chosen Zero Trust framework, you&#8217;ll want to incorporate a means of policy monitoring and enforcement. Prior to actually deploying the technology, however, you must define:<\/span><\/li><\/ul><ul><li aria-level=\"2\"><span style=\"font-weight: 400;\">How policy violations will be identified and flagged.\u00a0<\/span><ul><li><span style=\"font-weight: 400;\">Typical enforcement actions, both manual and automated.\u00a0<\/span><\/li><li><span style=\"font-weight: 400;\">The systems, assets, workflows, and applications to which a policy applies.<\/span><\/li><li><span style=\"font-weight: 400;\">Who is ultimately responsible for monitoring and enforcement.\u00a0<\/span><\/li><\/ul><\/li><\/ul><ul><li aria-level=\"1\"><b><span style=\"color: #003a5d;\">Acceptable use.<\/span> <\/b><span style=\"font-weight: 400;\">What systems and devices are allowed to connect to your network? If users are provided with company-owned devices, what are they allowed to <\/span><i><span style=\"font-weight: 400;\">do<\/span><\/i><span style=\"font-weight: 400;\"> with those devices, and what are the consequences of violating your acceptable use policy?\u00a0<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Access. <\/b><\/span><span style=\"font-weight: 400;\">Each asset should have its own set of access policies assigned to it. Permissions must be dynamic and adjustable based on the needs of individual users while also preventing lateral movement through your ecosystem.\u00a0<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Security awareness training. <\/b><\/span><span style=\"font-weight: 400;\">This includes how frequently training sessions and simulations will be run, what those sessions involve, and who must participate. Security awareness training policies must also define how you will assess each user&#8217;s knowledge, and what can be done in the event that a user fails their training.\u00a0<\/span><\/li><\/ul><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Assets. <\/b><\/span><span style=\"font-weight: 400;\">Map your network and clearly define each asset in terms of its criticality to business operations and the damage you might suffer should it be compromised.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Risk management. <\/b><\/span><span style=\"font-weight: 400;\">Determine a framework\/process for identifying, classifying, and mitigating risks and vulnerabilities in your ecosystem. NIST&#8217;s <\/span><a href=\"https:\/\/csrc.nist.gov\/projects\/risk-management\/about-rmf\"><span style=\"font-weight: 400;\">Risk Management Framework <\/span><\/a><span style=\"font-weight: 400;\">is an excellent starting point in that regard.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Incident response. <\/b><\/span><span style=\"font-weight: 400;\">Define a concrete management, communication, response, and recovery plan for each type of incident your business is likely to face, with a generalized plan flexible enough to be applied in the event of an unexpected crisis. Said plans must encompass:\u00a0<\/span><ul><li aria-level=\"1\"><span style=\"font-weight: 400;\">Clearly-defined, practical goals.\u00a0\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Immediate critical actions, such as isolating infected machines from the network in the event of malware.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Chain of command.<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Roles and responsibilities.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Mechanisms for business continuity and disaster recovery.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Rules and standards for communicating with stakeholders.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">A template for public messaging\/releases.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Policies on incident classification.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Processes and rules for communicating with threat actors \u2014 for instance, whether or not your organization would ever pay off a ransomware distributor.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Alert and log management procedures.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"font-weight: 400;\">Post-incident evaluation and review.\u00a0<\/span><\/li><\/ul><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Usability assessments. <\/b><\/span><span style=\"font-weight: 400;\">You must have policies in place for assessing and addressing usability concerns. Said policies should also define what&#8217;s involved in performing routine usability checks, including scheduling.<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Lifecycle management. <\/b><\/span><span style=\"font-weight: 400;\">Ensure there are processes in place for the regular application of security updates and critical patches to software and systems. <\/span><\/li><\/ul><h2><span style=\"color: #003a5d;\"><strong>Technology<\/strong><\/span><\/h2><p><i><span style=\"font-weight: 400;\">Last but certainly not least, there&#8217;s technology. These are the tools and architectural components that are foundational to Zero Trust. If you&#8217;ve already read NIST 800-207, you already have an idea of what you need, and what this section will cover.\u00a0<\/span><\/i><b><\/b><\/p><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Policy engine. <\/b><\/span><span style=\"font-weight: 400;\">As defined by NIST, this includes the <\/span><i><span style=\"font-weight: 400;\">policy engine <\/span><\/i><span style=\"font-weight: 400;\">that determines whether or not to grant access to a resource, a <\/span><i><span style=\"font-weight: 400;\">policy administrator <\/span><\/i><span style=\"font-weight: 400;\">that handles authentication and establishes a connection, and a <\/span><i><span style=\"font-weight: 400;\">policy enforcement point <\/span><\/i><span style=\"font-weight: 400;\">that enables, monitors, and terminates the connection. A policy engine is typically informed by:\u00a0<\/span><ul><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Threat intelligence. <\/b><\/span><span style=\"font-weight: 400;\">Information, both internal and external, gathered in real-time by solutions such as Endpoint Detection and Response\/Extended Detection and Response (EDR\/XDR).\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Real-time diagnostics related to the asset. <\/b><\/span><span style=\"font-weight: 400;\">This includes asset integrity, the presence of any known vulnerabilities, and the presence of any suspicious or unauthorized components.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Regulatory compliance systems. <\/b><\/span><span style=\"font-weight: 400;\">Solutions that automate the process of compliance enforcement wherever possible.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Network and system activity logs. <\/b><\/span><span style=\"font-weight: 400;\">Includes all events related to user activity, network activity, and system activity.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Access policies. <\/b><\/span><span style=\"font-weight: 400;\">Attributes, rules, and policies governing access to enterprise resources, either generated within the policy engine or defined via an external tool.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Enterprise public key infrastructure (PKI).<\/b><\/span><span style=\"font-weight: 400;\"> Generates and logs access certificates. <\/span><b>\u00a0<\/b><\/li><li aria-level=\"1\"><b><span style=\"color: #003a5d;\">Identity and Access Management (IAM).<\/span>\u00a0 <\/b><span style=\"font-weight: 400;\">A collective framework of tools, technologies, and policies to create, store, and manage permissions for user accounts.\u00a0<\/span><\/li><li aria-level=\"1\"><span style=\"color: #003a5d;\"><b>Security Information and Event Management (SIEM). <\/b><\/span><span style=\"font-weight: 400;\">Combines threat detection, compliance, and security incident management into a single platform, while also aggregating and analyzing log and event data. Typically also manages and classifies security alerts.\u00a0<\/span><\/li><\/ul><\/li><li><span style=\"color: #003a5d;\"><b>Endpoint\/Extended Detection and Response (EDR\/XDR). <\/b><\/span><span style=\"font-weight: 400;\">EDR continuously monitors both endpoints and end-user devices within your ecosystem to help security teams identify and remediate threats. XDR serves the same purpose, but expands its scope beyond endpoints to cloud applications, email, etc.\u00a0<\/span><\/li><li><span style=\"color: #003a5d;\"><b>Single Sign On (SSO). <\/b><\/span><span style=\"font-weight: 400;\">Facilitates ease of access to your organization&#8217;s resources, allowing an authorized user to authenticate to all relevant systems and applications simultaneously rather than having to login to each one individually.<\/span><\/li><li><span style=\"color: #003a5d;\"><b>Multi-Factor Authentication (MFA). <\/b><\/span><span style=\"font-weight: 400;\">Provides an additional layer of verification for users beyond a simple username and password. This in turn makes it considerably more difficult for a threat actor to gain access to a compromised account.\u00a0<\/span><\/li><li><span style=\"color: #003a5d;\"><b>Sandboxing. <\/b><\/span><span style=\"font-weight: 400;\">Arguably crucial to the concept of Least Privilege, containerization helps ensure that even if a threat actor uses a compromised account to gain access to an application or access, they are unable to move laterally through the network.\u00a0<\/span><\/li><li><span style=\"color: #003a5d;\"><b>Software-defined network perimeters. <\/b><\/span><span style=\"font-weight: 400;\">Tangentially related to IAM and sandboxing, a software-defined perimeter controls access to assets by forming virtual boundaries based on a user&#8217;s identity, location, etc.\u00a0<\/span><\/li><li><span style=\"color: #003a5d;\"><b>Data Loss Prevention\/Data Leak Prevention (DLP). <\/b><\/span><span style=\"font-weight: 400;\">Solutions that respectively prevent data from being rendered inaccessible through cyber incidents such as ransomware and from being transmitted to unauthorized parties outside your organization.\u00a0<\/span><\/li><\/ul><h2><span style=\"color: #003a5d;\"><strong>Trust No One, Verify Everyone<\/strong><\/span><\/h2><p><span style=\"font-weight: 400;\">Whether you&#8217;re an SMB or a large enterprise, the threat landscape you now face is both sophisticated and ever-changing.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">A traditional, perimeter-based approach to cybersecurity simply cannot contend with emerging threats, nor can it effectively support distributed work. In order to protect your people, systems, and data, you need to change how you think about cybersecurity.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">And that starts with embracing Zero Trust. Book a discovery call today and we\u2019ll help you create a plan to embrace Zero Trust in your organization.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-898f9dc elementor-align-left elementor-invisible elementor-widget elementor-widget-button\" data-id=\"898f9dc\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeIn&quot;,&quot;_animation_delay&quot;:200}\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-size-sm\" role=\"button\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Contact us today<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-896a845 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"896a845\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-dfb0f93\" data-id=\"dfb0f93\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-058600a elementor-widget elementor-widget-image\" data-id=\"058600a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/09\/Indigo-E-Book-Thumbnail-2.png\" title=\"\" alt=\"\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-351e8ec\" data-id=\"351e8ec\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e4b6f30 elementor-invisible elementor-widget elementor-widget-heading\" data-id=\"e4b6f30\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInRight&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Interested in learning more about Agile Development for IAM Solutions? Download our eBook today!<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b09e95d elementor-align-left elementor-invisible elementor-widget elementor-widget-button\" data-id=\"b09e95d\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInRight&quot;,&quot;_animation_delay&quot;:200}\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.indigoconsulting.ca\/fr\/ebook\/ebook-agile-development\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">DOWNLOAD EBOOK<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>The early days of network security were defined by static, nigh-immutable perimeters. Every user and asset inside that perimeter was treated with implicit trust. This worked well enough in a world where in-office work was the norm and cybercriminals operated largely independently of one another. How things have changed. We now live in a world [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":3489,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[117],"tags":[],"class_list":["post-3487","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.8 (Yoast SEO v28.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Zero Trust Checklist | Indigo Consulting Insights<\/title>\n<meta name=\"description\" content=\"How can your organization get started with Zero Trust? Read our checklist to learn more about what you need, where to start, and other insights.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.indigoconsulting.ca\/fr\/blog\/zero-trust-cybersecurity-checklist\/\" \/>\n<meta property=\"og:locale\" content=\"fr_CA\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Embracing zero trust cybersecurity: A checklist to get you started\" \/>\n<meta property=\"og:description\" content=\"How can your organization get started with Zero Trust? Read our checklist to learn more about what you need, where to start, and other insights.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.indigoconsulting.ca\/fr\/blog\/zero-trust-cybersecurity-checklist\/\" \/>\n<meta property=\"og:site_name\" content=\"Indigo Consulting\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-21T15:14:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-11-21T17:08:33+00:00\" \/>\n<meta name=\"author\" content=\"Web Master\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Web Master\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Zero Trust Checklist | Indigo Consulting Insights","description":"How can your organization get started with Zero Trust? Read our checklist to learn more about what you need, where to start, and other insights.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.indigoconsulting.ca\/fr\/blog\/zero-trust-cybersecurity-checklist\/","og_locale":"fr_CA","og_type":"article","og_title":"Embracing zero trust cybersecurity: A checklist to get you started","og_description":"How can your organization get started with Zero Trust? Read our checklist to learn more about what you need, where to start, and other insights.","og_url":"https:\/\/www.indigoconsulting.ca\/fr\/blog\/zero-trust-cybersecurity-checklist\/","og_site_name":"Indigo Consulting","article_published_time":"2022-11-21T15:14:42+00:00","article_modified_time":"2022-11-21T17:08:33+00:00","author":"Web Master","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Web Master","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/#article","isPartOf":{"@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/"},"author":{"name":"Web Master","@id":"https:\/\/www.indigoconsulting.ca\/#\/schema\/person\/38f543d7b3a9f166761affde4e68fb3f"},"headline":"Embracing zero trust cybersecurity: A checklist to get you started","datePublished":"2022-11-21T15:14:42+00:00","dateModified":"2022-11-21T17:08:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/"},"wordCount":1846,"publisher":{"@id":"https:\/\/www.indigoconsulting.ca\/#organization"},"image":{"@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/#primaryimage"},"thumbnailUrl":"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-scaled.jpg","articleSection":["Blog"],"inLanguage":"fr-CA"},{"@type":"WebPage","@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/","url":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/","name":"Zero Trust Checklist | Indigo Consulting Insights","isPartOf":{"@id":"https:\/\/www.indigoconsulting.ca\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/#primaryimage"},"image":{"@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/#primaryimage"},"thumbnailUrl":"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-scaled.jpg","datePublished":"2022-11-21T15:14:42+00:00","dateModified":"2022-11-21T17:08:33+00:00","description":"How can your organization get started with Zero Trust? Read our checklist to learn more about what you need, where to start, and other insights.","breadcrumb":{"@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/#breadcrumb"},"inLanguage":"fr-CA","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/"]}]},{"@type":"ImageObject","inLanguage":"fr-CA","@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/#primaryimage","url":"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-scaled.jpg","contentUrl":"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2022\/11\/young-contemporary-cyber-security-manager-typing-i-2021-12-09-20-56-00-utc-scaled.jpg","width":2560,"height":1709,"caption":"Young contemporary cyber security manager typing while sitting by desk in front of computer monitors"},{"@type":"BreadcrumbList","@id":"https:\/\/www.indigoconsulting.ca\/blog\/zero-trust-cybersecurity-checklist\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.indigoconsulting.ca\/"},{"@type":"ListItem","position":2,"name":"Embracing zero trust cybersecurity: A checklist to get you started"}]},{"@type":"WebSite","@id":"https:\/\/www.indigoconsulting.ca\/#website","url":"https:\/\/www.indigoconsulting.ca\/","name":"Indigo Consulting","description":"A Leading IAM, Compliance, &amp; IT Consultant","publisher":{"@id":"https:\/\/www.indigoconsulting.ca\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.indigoconsulting.ca\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-CA"},{"@type":"Organization","@id":"https:\/\/www.indigoconsulting.ca\/#organization","name":"Indigo Consulting","url":"https:\/\/www.indigoconsulting.ca\/","logo":{"@type":"ImageObject","inLanguage":"fr-CA","@id":"https:\/\/www.indigoconsulting.ca\/#\/schema\/logo\/image\/","url":"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2020\/03\/logo_indigo.png","contentUrl":"https:\/\/www.indigoconsulting.ca\/wp-content\/uploads\/2020\/03\/logo_indigo.png","width":363,"height":109,"caption":"Indigo Consulting"},"image":{"@id":"https:\/\/www.indigoconsulting.ca\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/indigo-technologies-canada-inc.\/"]},{"@type":"Person","@id":"https:\/\/www.indigoconsulting.ca\/#\/schema\/person\/38f543d7b3a9f166761affde4e68fb3f","name":"Web Master","image":{"@type":"ImageObject","inLanguage":"fr-CA","@id":"https:\/\/secure.gravatar.com\/avatar\/545c64cbccfbdd8a03700444efeb701f8d8efbce05186f326dae06e6d17e5575?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/545c64cbccfbdd8a03700444efeb701f8d8efbce05186f326dae06e6d17e5575?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/545c64cbccfbdd8a03700444efeb701f8d8efbce05186f326dae06e6d17e5575?s=96&d=mm&r=g","caption":"Web Master"},"url":"https:\/\/www.indigoconsulting.ca\/fr\/author\/webmaster\/"}]}},"_links":{"self":[{"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/posts\/3487","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/comments?post=3487"}],"version-history":[{"count":0,"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/posts\/3487\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/media\/3489"}],"wp:attachment":[{"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/media?parent=3487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/categories?post=3487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.indigoconsulting.ca\/fr\/wp-json\/wp\/v2\/tags?post=3487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}