draft When the federal government makes a strategic decision to implement Zero Trust principles, they must consider both user identity and the data users are trying to access.
Today, we have leaders in the federal and commercial sectors look at both data and identity and emphasize the need for centralized coordination, automated labeling, and real-time access control through Identity Management.
Brian Rosensteel from Ping Identity argues that some kind of “federated” identity management system is the most effective for federal identification. Each agency really cannot be responsible for responding in a timely manner given the details that Zero Trust demands.
Access controls have been around since the start of networks. During the discussion, participants gave opinions on the value of both access based and role-based access controls. They also suggested that “context” based access controls may provide additional abilities for systems administrators to improve real-time access controls.