Which element of ZT focuses on the governance rules that definethe "who, what, when, how, and why" aspects of accessing targetresources?
D) Never trust, always verify
Policy is the element of ZT that focuses on the governance rules that define the ''who, what, when, how, and why'' aspects of accessing target resources. Policy is the core component of a ZTA that determines the access decisions and controls for each request based on various attributes and factors, such as user identity, device posture, network location, resource sensitivity, and environmental context. Policy is also the element that enables the ZT principles of ''never trust, always verify'' and ''scrutinize explicitly'' by enforcing granular, dynamic, and data-driven rules for each access request.
Reference=
Certificate of Competence in Zero Trust (CCZT) prepkit, page 14, section 2.2.2
What Is Zero Trust Architecture (ZTA)? - F5, section ''Policy Engine''
Zero Trust Architecture Project - NIST Computer Security Resource Center, slide 9
[Zero Trust Frameworks Architecture Guide - Cisco], page 4, section ''Policy Decision Point''
Maryln
7 months agoCecil
7 months agoRichelle
7 months agoArthur
7 months agoArt
8 months agoPhung
8 months agoGeraldo
8 months agoVince
8 months agoShawna
9 months agoDarrin
9 months agoCiara
9 months agoRaylene
9 months agoPaul
9 months agoVeronika
12 months agoDallas
12 months agoTheresia
12 months agoAnnett
12 months agoFletcher
11 months agoMarget
11 months agoJolene
12 months agoClorinda
1 year agoEstrella
1 year agoRodney
11 months agoDottie
11 months agoLon
11 months ago