Gartner Research

2023年零信任安全项目实施战略路线图

Published: 19 July 2023

Summary

零信任安全架构采用动态的显式信任模型,取代传统安全架构中静态的隐式信任模型。安全和风险管理领导者须为零信任项目制定清晰的路线图,优化企业机构的风险态势。

Included in Full Research

概述

主要发现
  • 北美和其他地区的企业机构强烈希望采用零信任安全范式,以降低自身的安全风险,但在操作层面却很难将此想法转化为可行的战略,以及确定路线图、项目和可衡量的成果。

  • 供应商大肆宣传“零信任”,让企业机构认为可以通过采购相关产品提高安全性,但零信任并非特指某一种技术。零信任作为一种范式,会对适用于各种技术的网络安全原则进行重组和强调,以应对企业机构面临的特定风险。

  • 如果缺乏清晰的战略和周密的规划,企业机构的技术实施可能会缺乏完整性,造成时间和资源的浪费,并可能产生错误的安全感。战略制定的常见阻碍因素包括遗留技术、可扩展性、零信任技术实施中的集成和能力差距、企业机构的内部阻力,以及未能考虑对业务流程的影响。

  • 零信任技术的实施会产生高额的运营性间接成本,特别是在企业机构没有明确定义“谁有权访问什么”,并且没有集成技术控制以适应环境变化的情况下。

建议

负责领导零信任项目以改善基础设施安全的安全和风险管理领导者,应:

  • 明确具体用例,构建切实可行的零信任战略,例如通过限制恶意软件的横向移动或隔离软件供应链攻击,减少应用和服务的风险暴露,或缓解特定威胁。

  • 对身份与访问管理(IAM)技术和流程等当前环境进行评估,解决相关风险,针对关键用例制定企业机构的零信任战略和要求,然后再投资新的零信任技术。

  • 在项目的早期阶段,通过培养零信任思维、宣传项目对工作流和流程的预期影响,制定计划克服关键阻碍因素,如内部阻力。

  • 在技术评估过程中,强调可管理性、部署范围以及对用户体验的潜在影响。为零信任技术管理员明确可扩展的流程和技术,并利用运营保障实践来衡量控制措施的有效性。

Clients can log in to view the entire document.

Access Research

Already a Gartner client?

To view this research and much more, become a client.

Speak with a Gartner specialist to learn how you can access peer and practitioner research backed by proprietary data, insights, advice and tools to help you achieve stronger performance.

By clicking the "Continue" button, you are agreeing to the Gartner Terms of Use and Privacy Policy.

Gartner research: Trusted insight for executives and their teams

What is Gartner research?

Gartner research, which includes in-depth proprietary studies, peer and industry best practices, trend analysis and quantitative modeling, enables us to offer innovative approaches that can help you drive stronger, more sustainable business performance.

Gartner research is unique, thanks to:

Independence and objectivity

Our independence as a research firm enables our experts to provide unbiased advice you can trust.

Actionable insights

Not only is Gartner research unbiased, it also contains key take-aways and recommendations for impactful next steps.

Proprietary methodologies

Our research practices and procedures distill large volumes of data into clear, precise recommendations.

Gartner research is just one of our many offerings.

We provide actionable, objective insight to help organizations make smarter, faster decisions to stay ahead of disruption and accelerate growth.

Tap into our experts

We offer one-on-one guidance tailored to your mission-critical priorities.

Pick the right tools and providers

We work with you to select the best-fit providers and tools, so you avoid the costly repercussions of a poor decision.

Create a network

Connect directly with peers to discuss common issues and initiatives and accelerate, validate and solidify your strategy.

Experience Information Technology conferences

Join your peers for the unveiling of the latest insights at Gartner conferences.

©2022 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. and its affiliates. This publication may not be reproduced or distributed in any form without Gartner’s prior written permission. It consists of the opinions of Gartner’s research organization, which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, Gartner disclaims all warranties as to the accuracy, completeness or adequacy of such information. Although Gartner research may address legal and financial issues, Gartner does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by Gartner’s Usage Policy. Gartner prides itself on its reputation for independence and objectivity. Its research is produced independently by its research organization without input or influence from any third party. For further information, see Guiding Principles on Independence and Objectivity.