President Biden designated October as “Cybersecurity Awareness Month,” and the White House released a fact sheet updating the progress made on his May 2021 executive order on national cybersecurity. Updates include:
In light of the progress report, we re-read the “Executive Order on Improving the Nation’s Cybersecurity,” and how it directs the US Federal Government to move towards a Zero Trust cybersecurity architecture. What does this all mean?
May 2021, the Biden Administration released an executive order which codified the previous ‘best practice’ initiative between the federal government and Zero Trust security architecture. Before the May 12th declaration, each federal government agency had been responsible for setting its own cybersecurity policy, which in hindsight may not have been the best idea, given the numerous and serious breaches that have occurred in the recent past, most notably the SolarWinds breach and the OPM (Office of Personnel Management) hack.
Prior to 2021, at least three major government agencies—including the Department of Defense, the Department of Education, and the Small Business Administration—had already adopted Zero Trust or were putting it on their agenda. This gave them definitive advantages. Despite being a user of SolarWinds Orion software, the Department of Defense had reported that they remained unaffected by the SolarWinds breach.
By mandating that every government agency adopt Zero Trust architecture, the Biden administration is greatly increasing the security of data belonging to US citizens. What’s more, reading the executive order text reveals a deep and nuanced understanding of Zero Trust and what it entails.
Part of the Biden Administrations executive order requires all Federal Government systems to implement impactful cybersecurity measures, like multifactor authentication. The order also showcases a new budget for Federal agencies to be able to reach the cybersecurity goals set in place by the administration.
First, Zero Trust is among a holistic set of strategies, which also include securing cloud services, centralizing access to cybersecurity data, purchasing additional technology, and hiring new personnel. All of this is good—Zero Trust isn’t a single technology, so the government will need to invest in multiple new applications and staff who know how to use them.
Second, Zero Trust implementation will begin to take place rapidly. Government agencies must submit their plans to implement Zero Trust. These plans will conform to the government’s own migration steps, as laid down by the NIST, and will be reviewed by the president’s national security advisor. Agencies have until the end of September 2024 to meet the five zero trust goals: identity, devices, networks, applications and data.
The NIST guidelines on implementing Zero Trust are extensive and give an excellent roadmap for understanding and implementing the architecture.
Lastly, the executive order gives a working definition of Zero Trust architecture itself:
“The Zero Trust security model eliminates implicit trust in any one element, node, or service and instead requires continuous verification of the operational picture via real-time information from multiple sources to determine access and other system responses. In essence, a Zero Trust Architecture allows users full access but only to the bare minimum they need to perform their jobs.”
The executive order goes on to state that the Zero Trust security architecture is premised on the idea that a data breach is inevitable (if it hasn’t occurred already), introduces the concept of least privilege access, and identifies that Zero Trust must rely on granular controls. These are all excellent starting points for the creation of a Zero Trust network.
Through this executive order, the federal government is developing cybersecurity labels to be placed on routers, home cameras and other consumer IoT devices. This is to ensure that buyers are given the most up to date information on how safe the products they are buying are.
For any new IT security project to succeed, three things need to happen:
The executive order establishes all of these things, but there’s still a long road to travel. Government IT systems are legendarily underfunded, and in many cases obsolete. In 2015, 75% of the government’s $80 billion annual IT budget was devoted to hardware that should be at the end of life.
Government IT is older and it’s most likely from a variety of different vendors. This means that one of the big prerequisites of Zero Trust architecture—channeling information from multiple sources into a centralized location for continuous monitoring—is going to be that much harder to achieve. Either these agencies are going to have to rip and replace much of their pre-existing infrastructure, or they’re going to have to figure out better ways to integrate their security information.
Here at Garland Technology, we are a trusted visibility vendor for the US government and partner with many of the security tools they utilize. Implementing a Zero Trust visibility fabric starting with network TAPs, packet brokers and inline bypass gives government agencies the improved risk assessment, added asset visibility, reduced network complexity, and streamlined infrastructure upgrades they’ll need to build a true foundation for Zero Trust Architecture.
Looking to add TAP visibility or traffic aggregation to your Zero Trust deployment, but not sure where to start? Join us for a brief network Design-IT consultation or demo. No obligation - it’s what we love to do.
If the inline security tool goes off-line, the TAP will bypass the tool and automatically keep the link flowing. The Bypass TAP does this by sending heartbeat packets to the inline security tool. As long as the inline security tool is on-line, the heartbeat packets will be returned to the TAP, and the link traffic will continue to flow through the inline security tool.
If the heartbeat packets are not returned to the TAP (indicating that the inline security tool has gone off-line), the TAP will automatically 'bypass' the inline security tool and keep the link traffic flowing. The TAP also removes the heartbeat packets before sending the network traffic back onto the critical link.
While the TAP is in bypass mode, it continues to send heartbeat packets out to the inline security tool so that once the tool is back on-line, it will begin returning the heartbeat packets back to the TAP indicating that the tool is ready to go back to work. The TAP will then direct the network traffic back through the inline security tool along with the heartbeat packets placing the tool back inline.
Some of you may have noticed a flaw in the logic behind this solution! You say, “What if the TAP should fail because it is also in-line? Then the link will also fail!” The TAP would now be considered a point of failure. That is a good catch – but in our blog on Bypass vs. Failsafe, I explained that if a TAP were to fail or lose power, it must provide failsafe protection to the link it is attached to. So our network TAP will go into Failsafe mode keeping the link flowing.
Single point of failure: a risk to an IT network if one part of the system brings down a larger part of the entire system.
Heartbeat packet: a soft detection technology that monitors the health of inline appliances. Read the heartbeat packet blog here.
Critical link: the connection between two or more network devices or appliances that if the connection fails then the network is disrupted.