Skip to content(if available)orjump to list(if available)

Breaking Down the NSA's Guidance on Zero Trust Implementations (2024)

cyrnel

There's not a lot of "breaking down" happening here. It's the same vague recommendations that can be found in the NSA's own documents, further reinforcing the gap between the guidelines and practitioners.

NSA/NIST/CISA all admirably avoid referring to specific products, but that ship has already sailed. Security today _is_ (unfortunately) a constellation of security products, rather than open source protocols, etc.

meltyness

Pessimistically, if you have a product you want to sell to the government, this stuff is all just "veto bingo" where someone could turn you down, or move development.

Optimistically, it exposes clear marketable opportunities in existing suites.

null

[deleted]