flâneur — a map of the web's best reading

BeyondCorp is dead, long live BeyondCorp

mayakaczorowski.com · 1,983 words · saved by 1 readers

With the US government’s recent memo on Zero Trust Cybersecurity Principles, there’s renewed interest (and investment) from organizations in adopting zero trust architectures. BeyondCorp, Google’s initial implementation which spawned the pursuit of zero trust in general, is still the guiding star for many organizations. It would seem that the authors of the US government’s memo have, just like the rest of the security industry, read the BeyondCorp whitepapers—and heavily based their strategy on BeyondCorp. In reality, however, no organization has successfully implemented a fully zero trust architecture, and many proponents of zero trust—including the US government—have missed a key component: devices. Let’s ignore the memo’s recommendations on DNSSEC and STARTTLS, and focus just on the zero trust architecture. Traditional network architecture relied on a network perimeter to delineate between trusted and untrusted users, such as trusted employees inside a firewall, vs. potentially untr

With the US government’s recent memo on Zero Trust Cybersecurity Principles , there’s renewed interest (and investment) from organizations in adopting zero trust architectures. BeyondCorp , Google’s initial implementation which spawned the pursuit of zero trust in general, is still the guiding star for many organizations. It would seem that the authors of the US government’s memo have, just like the rest of the security industry, read the BeyondCorp whitepapers – and heavily based their strategy on BeyondCorp. In reality, however, no organization has successfully implemented a fully zero trust

Explore this link on the map →

related reading