Forrester develops Zero Trust model for IT security

Thursday, September 30, 2010

Forrester Research is releasing a report that attempts to retool the way IT companies protect their information by introducing a “trust no one” model.

The new model, called Zero Trust, attempts to minimize holes in IT security strategies by making security ubiquitous throughout the network, not just at the perimeter, as is commonly practiced today.

Insider threat to data security has become increasingly prevalent in recent years. Well-organized cybercriminals have recruited insiders and developed new attack methods to breach information networks.

In its new report titled “Introducing the Zero Trust Model of Information Network,” Forrester Research attempts to retire the commonly used IT security strategy that researcher John Kindervag likens to an M&M - hard on the outside, soft on the inside.

“In today’s new threat landscape, this is no longer an effective way of enforcing security,” Kindervag stated. “Once an attacker gets past the shell, he has access to all the resources in our network.”

A recent report by Verizon found that data misuse and social breaches increased significantly in the last year. Nearly half of all breaches were attributed to users that abused their right to access corporate information for malicious purposes, the report states.