Marke: Jordan O'Neal
Variante: Taschenbuch
Eigenschaften:
This book was written for the practitioner: the security architect, the network engineer, the identity team lead, the person responsible for building and operating zero-trust controls.The perimeter is gone. Attackers no longer break through the front door; they exploit over-privileged credentials and move laterally through flat networks for weeks before detection. Each undetected hop expands the blast radius, turning a single compromised endpoint into an organization-wide crisis. Zero trust architecture answers with a clear principle: no user, device, or workload is trusted by default. Every access request is verified, every session continuously monitored, and every segment enforced to stop what cannot be prevented. This book is the practitioner-grade blueprint for building that architecture across real hybrid enterprises.Inside this book, readers will learn how to:Verify every identity: Apply continuous verification across users, service accounts, and workloads using identity frameworks aligned with NIST 800-207, EO 14028, and OMB M-22-09.Architect microsegmentation: Design granular network segments that isolate workloads, limit lateral movement, and shrink blast radius in cloud and on-premises environments.Deploy policy decision points and policy enforcement points: Build the control-plane components that evaluate context-aware access requests and translate policy into enforceable action at every segment boundary.Satisfy compliance mandates: Map zero trust controls to CMMC, FISMA, HIPAA, PCI-DSS, SOX, GDPR, and SOC 2 so security investments simultaneously produce audit-ready evidence.Contain breaches before they cascade: Implement workflows that localize incidents, trigger automated containment, and stop the lateral movement patterns that turn intrusions into disclosures.Integrate into hybrid enterprises: Apply consistent identity-centric controls across on-premises, multi-cloud, and SaaS estates without requiring a ground-up rebuild.Build defensible architecture documentation: Produce policy statements, data-flow diagrams, and risk rationale that secure executive buy-in and satisfy auditors under FISMA and CMMC reviews.Evaluate vendor capabilities objectively: Align product features to NIST 800-207 control categories and your organization's threat model to cut through marketing noise.The book serves two intersecting audiences. Security architects and engineers will find deep-dive specifics: identity provider federation, microsegmentation rule construction, telemetry pipelines, and policy-as-code automation. Security managers and leaders will find decision frameworks that translate architectural choices into risk language and compliance alignment. The most dangerous gap in any security program is the distance between what engineers build and what leaders authorize.Every architecture pattern is grounded in scenario-driven analysis from real deployment challenges in regulated industries and federal environments, covering both commercial compliance regimes and the federal zero trust mandates reshaping sector-wide expectations. Threading every chapter is the Marcus Reyes continuing case study, a senior security architect navigating a full zero trust transformation. His decisions and trade-offs give abstract principles operational weight.Security is not a product state; it is an architectural commitment renewed with every access decision and every new workload deployed. Organizations that weather the next generation of threats are those whose architects have designed the control planes, drawn the trust boundaries, and built the continuous verification pipelines that make breach containment a property of the system. That work is a professional obligation. Begin building it now.