Implementing Zero Trust Approach via PAM36018 minutes to read
Zero Trust - Policy-Based Access PrivilegeZero Trust is the trending methodology of granting access privileges to users to the resources in an organization by verifying their activities and state with the score-based access policy method instead of trusting them instinctively, irrespective of their identity. The foremost motto of this approach is never to trust and always verify before granting privileges in an organization. By formulating real-time user/resource scores, the Zero Trust approach highlights vulnerable users and non-compliant devices, thus restricting further access privileges to the users and the resources via policy-based access privilege methodologies. Zero Trust Approach in PAM360Where does this Zero Trust Approach Benefit the organization? This document will help you learn more about implementing the Zero Trust approach in your organization via PAM360. Refer to the below sub-sections to learn more about the further Zero Trust implementation process:
1. User RolesZero Trust configuration involves four main operations: configuring parameters and trust score weightage, configuring access policies, approving access policy requests, and resolving conflicts between access policies for a resource. By default, users with:
If you require a custom user role to meet your specific needs, you can navigate to 'Admin >> Customization >> Roles >> Zero Trust' and enable the necessary permissions that follow:
2. Installing PAM360 Agent with Zero Trust ModuleThe Zero Trust methodology works in an organization based on access policies defined via a set of score parameters. For the policy-based access privilege feature to fetch data for different parameters from user devices and resources for score validations, an agent with the relevant usage type is to be installed in the respective user devices and resources that come under the Zero Trust approach for privileged access and account governance. To fetch data for User Score Parameters, an agent with the usage type 'User Device' is to be installed in the user machines. Similarly, an agent with the usage type 'Resource' should be installed in all the resources with the enabled Zero Trust Module to fetch the data for Resource Score Parameters. Note: If you want to implement the policy-based access control via the Zero Trust feature in an agentless approach, you can proceed with user authentication parameters for configuring the parameters, weightage and access policy. Refer to this help section to learn more about installing the PAM360 agent in the required user devices and resources. 3. Configuring Trust Score ParametersThe Zero Trust approach is micro-segment behavioral analytics of users and resources based on the predefined parameters for the trust score calculation. Nineteen types of parameters revolve around the Zero Trust approach in PAM360 for the trust score calculation. They are organized into two different categories:
In the Admin >> Zero Trust >> Configuration page, you can set the desired baseline passing value for those parameters for the trust score calculation as per your organization's needs. To know more about each parameter in detail and about defining the parametric conditions for trust score calculation, refer to this help document. Once the Zero Trust approach is implemented in your organization, users must maintain those minimum predefined conditional parameters to maintain their trust scores high, thus granting them access to privileged accounts or elevating their self-privileges based on the administrator's configuration. 4. Configuring Weightage for Trust ScoresConfiguring upon the parameter weightage in this section, the user trust score will be calculated based on user authentication and user device configuration/security postures, and the resource trust score will be calculated based on resource configuration/security postures. The calculated trust scores will be shown in the Users and Resources tabs beside the respective users and the resources. To configure the trust score weightage for the user score parameters:
Notes: Similarly, to configure the trust score weightage for the resource score parameters:
From the Trust Score page, you can also modify or define the condition parameters that are defined or left in the Admin >> Zero Trust >> Configuration page. To do so:
| |