Zero-Trust (ZT) Cyber Security
CIOREVIEW >> Cloud Africa >> NEWS

Director of Information System Security (ISS) at Commercial Bank of Ethiopia

SeyoumDamtew

Zero-Trust (ZT) Cyber Security

SeyoumDamtew

Currently I am working as director of information system security for commercial bank of Ethiopia, prior to this I worked atEthiotelecom as security operation center manager with a total of 18 years plus experience.

Recent cyber security research shows that above 90 percent cyber security attack is happened from internal network due to malware reached to the victim computer via phishing  (email, social network…), or by rogue employees who deliberately attack their owncompany for different reasons like financial, political, hobby.

Moreover, the experience of financial and telecom fraud happens mainly either with direct involvement of internal employees and external fraudsters with the support of internal employees.

Hence, reorganizing people, process and technology rollout in such a way that trusting after verifying is a key i.ezero trust architectureand continuous awareness to createhuman firewall.

Zero Trust Architecture

Zero Trust is not a system or program, but rather a set of rules and guidelines on how to secure a corporate network. The essence of the concept is ‘trust but verify’. In addition, more precisely, ‘first check, then double-check and keep checking until you reach zero trust’.When people first implemented network security (configuring firewall), they created a perimeter within which everyone trusted each other and had shared access to resources. The concept of zero trust, on the contrary, is based on a distrust of everyone and everything that is inside or outside the network perimeter.

  The concept of zero trust, is based on a distrust of everyone and everything that is inside or outside the network perimeter 

Previously firewalls only have inside zone (trusted), outside zone (untrusted) and DMZ zone for public use north to south approach, and mostly internal server to server and internal employees to server can communicate without limit, with zero trust there is no such configuration rather , all communications will be analyzed and verified and will be monitored 24/7.

This rigorous ‘trust no one’ security framework requires that all users, whether they are inside or outside of a business’s network, must be continuously validated using multiple authentication methods, and even lateral moves within a network must be continuously reassessed and reauthorized.  

Zero Trust Strategy Themes

Zero Trust Architecture Strategy

1. Permanent Access Control

There are no reliable sources in the zero trust model, all of them are questioned. Each request to access a system is authenticated, authorized, and encrypted.

a. User

b. Location

c. Application

d. Devices

e. Access Control Gates, Network Access Control

f. Physical Security (CCTV)

2. Preventive Methods of Protection

a. Multi-factor authentication,

b. Biometric based authentication

c. Least privilege access,

d. Micro-segmentation,

e. Email protection,

f. Orchestration,

g. Encryption,

h. Cloud access security brokers, etc.

i. End point detection and response (EDR)

j. Not only north to south control but also east to west by applying datacenter security (DCS)

k. Implement APT (advanced persistence threat)

3. Real Time Security Incident and Fraud Monitoring, Detection and Response

a. This is important to shorten the ‘breakout time’ — the gap between when a hacker breaks into the first system and when they move on to other systems on the network. Constant monitoring helps to repel threats when their scale is still minimal, i.e. at real time

b. SOC

c. SOAR

d. Malware

e. Artificial intelligence driven fraud management

f. End point detection and response

g. Deception/honey port

4. Consistency with the Security and Fraud Strategy and Governance

a. The Zero Trust security model is part of a comprehensive cyber resilience strategy that involves monitoring and addressing threats. Companies also check and update old authentication protocols, and fix and update all devices, programs, and firmware as soon as critical vulnerabilities are found.

b. Patch management

c. SSDLC

d. Sec-dev-ops

e. Security by design

f. Supply chain security

g. 3rd party security clearance

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.