Federal Forum 2022 - Embracing Zero Trust for a Resilient Federal Government
[Music] okay so up next we'll sit down with the department of health and human services to discuss how they're modernizing legacy applications and implementing a seamless zero trust security strategy to combat challenges please join me in welcoming our moderator ben de bont chief information security officer at servicenow and gerald caron chief information officer and assistant inspector general of information technology within department of health and human services office of inspector general [Music] thank you steve and thank you to all of you our wonderful it partners for taking the time to listen in today on this lightning chat an extremely complex and fascinating topic that is xero trust so jerry before you rack your brains on xero trust would you mind sharing a little bit more about your current role at hhs certainly it's great to see humans uh in person for once uh it's been a while but yes i'm the chief information officer at the department of health and human services office the inspector general uh basically and responsible for all i.t that supports the inspector general's mission of fraud waste and abuse medicaid medicare fraud all those great things that health care provides so support that mission of the auditors the investigators the litigators in doing that and bringing them the best i.t possible so that they can be successful thanks jerry so if we were at a a security conference and there's been many security conferences where there's been sessions on xeros trust thousands of them i have i'm confident that i could walk up to anyone in the audience and if i ask them their opinion on what zero trust is i would get a different answer a way to get a different response on what the value is that it provides and also a different response on how to execute against it or implement it or deploy it so jerry what does zero trusts mean to you it means by employment keeps me busy but no zero trust is is bit very important to me um i'm an evangelist um educator i like to say around zero trust been doing it for for years but to me if i had to say what does it mean to me at the end of the day you got to think about what it is that you're protecting and you're trying to protect the data a lot of people will argue with me it's about the identity well yes identity is very important but i would challenge that with if it was about the identity and you got compromised what's the first thing the cyber analyst is going to ask what did you have access to and is there x film right so what does it become about becomes about the data again so basically understanding your data what is your data and when you do talk about the identity right data the right people at the right time and make sure that that data has the integrity something that they can trust because that's what we make our everyday decisions on what facilitates access to that data it's applications applications sits on devices and devices communicate through networks so moving back kind of like the osi model moving back how do i protect around data what are the concepts around that how what facilitates the access to that data concepts around applications then devices network and then the identity and there's different identities we're all one human so we need to be able to understand all those different identities that are tied to that human as well as the different levels of those identities admins users power users things like that so jerry in cyber security it is a field where there's new vulnerabilities old vulnerabilities breaches every day you read about it in the news and this has been ongoing year after year for decades and as technology becomes more pervasive in our lives the attack surface that an attacker can exploit continues to grow so i very much feel that it is very difficult to defend and in many ways trivial to attack given what you said about data securing data isn't a new concept how does applying zero trust help protect ourselves from attack so first of all zero trust is not one tool or one solution it is an architecture made up of a bunch of concepts that you got that have to work together in conjunction there's many factors that you have to constantly assess the types of users how did they proof themselves what is my risk level for that proofing like username and password is going to be more risky than a pif card for example or a cat card um taking those factors into um consideration and doing it in real time i like to use um we got to get away from you know everybody says the castle i say the tootsie roll pop right we know mr al bit licked the tootsie roll pap three times and then he broke security by using his beak to get through on the third lick um so you know and then get to that soft gooey center we can't do that we have to move our control not our controls i don't want to say controls uh necessarily because we want to move forward effectiveness and control this kind of more towards compliance and in the federal government of course but we want to move things closer to the data and the things that we're protecting you know the cafeteria schedule versus your medical records i want to make sure the cafeteria schedule gets compromised i can assure you that your medical records are still protected so getting away from this big boundary and having that soft gui center like we had before but moving those boundaries in those concepts even segmenting within databases and things like that i like to use the movie theater scenario i know i go to the multiplex movie theater it doesn't start to go into the movies again and where do they scan my ticket they scan my ticket at the lobby well in xero trust they should be scanning my ticket at each movie door because i bought a ticket to go see the regular but hey the imax is going in five minutes i'm just gonna slip in there well there's no ticket taker at that door and there's no usher's coming to check am i in the right seat is the camera working are the lights down is everybody in the right seat are in the movies you got to constantly check so that's like ongoing authentication ongoing access and there's a bunch of factors that you have to constantly check and i and listening to the general before is like we got to do this in real time right we can't wait on humans to identify hey something's wrong there let me try to figure that out and zero trust has got to be automated it's got to all work together all those factors from all those tools have to come about so that you can whoa i'll start over [Laughter] so you got to take and measure all these factors so we can talk about technology a lot but i think some people miss the conversation of the methodology and understanding the risk and what your risk tolerances are you have to build those different risk tolerances based off those factors so that if it reaches a factor let's say something gets triggered you had full access but something happened i'm not really sure i may downgrade you to you can read only but i'm not going to let you download a print or i may if i have the ability block you or quarantine you and if i have control like an mdm i can bring you back into compliance if i don't which is a higher risk i may just block you completely so we could go on forever jerry um you mentioned that the movie theater example by having a ticket scan multiple times i admit that back in australia i might have seen an extra movie when i only had a ticket for one in the past when i was a kid but doing that multiple scanning and you did say it needs to be automated that type of approach that's easier said than done how is it practical for an agency to go ahead and automate authentication so that you don't trust anything but you do constantly verify in a way that doesn't slow you down well i'm going to back up a little bit first it's understanding what your data the data is and one of the things that we're going to be doing is going to identify a data source and we're going to understand the baseline of where that data is going where is it where is it flowing i'm not doing network mapping that's different i'm talking about data mapping taking an application and mapping the data where is it hooking where is it talking to where's that data flowing i got to know what normal looks like before i can say what is abnormal um so really got to understand that baseline in reference to what you're talking about in the authentication aspects it's going to be an ongoing authentication and an ongoing access i need to check these factors there's things like in the cloud you know taking advantage of the cloud conditional access policies impossible travel you were in dc but you're in australia in five minutes later i got to do something right so i can't just do this linearly one time through the door have a nice day i i have to constantly keep checking now you ask about like the user and alluding to like the performance of a user and how do i how do i maintain that well i am employing my users as part of my zero trust team early on i'm educating them hey we're gonna be talking about this zero trust thing they're not i.t people so hey there's you're gonna hear about this zero trust thing things might change okay over the next few years but you know what i need to know how you want to work why because i want to incorporate that into my requirements so i can make zero trust seamless and i'm also talking to them about what are the benefits single sign-on uh better you know and pretty much more transparent it can be do be in the background it doesn't have to be put in a pin every five minutes so i can trust that you're still there and who you are um but just keep checking these factors and and being seamless but understand how they work and how well not how they work how they want to work where's the data they're accessing how are they accessing it and and and how are they authenticating what devices are they using what data is important to them and how are they making decisions and building that in because that's going to help the adoption so i i equate it to the playbook of a football team right you got the people on the field they're the ones that are going to implement my zero trust i get the sideline they're the ones that are my project managers program managers i get the executive suite you know the cfos making sure we get the resources the agency head that's prioritizing making sure that it's important that we do it but well who am i doing it for like i said at the beginning i am doing it oh hhsoig was not put on this earth to do i.t i.t is the enabler of hhs oig's mission they're the fans and i want to make sure that my fans are happy so i want to make sure that i incorporate their requirements as i go through this journey of zero trust and let them know the benefits that they're going to gain as i do that seamless single sign-on kind of things and things like that not tethering them back to a on-premises network just to go back out to the cloud where we're pretty much modernizing a lot of our legacy applications as well there's a long answer to a short question no it's a great answer jerry i was just thinking so now that the last year's executive order mandates embracing a zero trust approach has there been um like additional resources allocated to achieve this or is it expected to be achieved by existing resources and uh maybe to expand that a little bit further there are so many security cyber security requirements already in place how does how does an agency even wrap their head around what they need to achieve in addition to maintaining or at least still trying to meet the status quo for existing requirements yeah um yeah a lot to unpack there but um definitely the eo i look what i like about the eo it doesn't make it just an i.t thing it's it's it's now an agency thing the agency has to understand that this is important we have to improve the nation's cyber security so everybody pay attention to this not just the i.t people as far as um funding and things like that and resources um there is omb memo 22-09 that came out a little over a month ago and that pretty much says first year you know find out a way to pay for some things but start budgeting in because we do two-year budget cycles which are budgeting it into for 2024 but also you know a great resource and some some agencies have been successful in going through the process and i've actually submitted to the process there's a technology modernization fund that was some money set aside for the president to help with some of these modernization efforts not just zero trust um a few agencies have gotten that um you know submitted for that and getting that money um to the other part of your question about where to start you know we're all in different places and we're all in different levels of maturity um you know i kind of say the three the pillars um if they line up with dhs's pillars or not um but you know basically they will in some form fashion you know i talked about data um i talked about you know applications devices networks users things like that what i did is i have a zero trust capability functional capabilities model and if you're a vendor and you want to talk to me about xero trust you have a homework assignment and this would be your homework assignment under under all these columns i have functional capabilities what i did internally is even if it's a security tool or not what are all the technologies that i have at my fingertips without making another investment and then taking dhs's maturity model how well am i doing in that i may not be doing it okay that's red i may be doing it i'm doing very well according to the maturity model that's green okay don't have to worry about that one so much vendors also get that because no vendor one vendor does everything so i ask them what functions do you cover so even the ones i invested in you know i gave them also i said look i have an investment if i didn't spend another penny for another license what could i do in xero trust and you know provided that so definitely doing that inventory so i know what i can take advantage of with the concepts of xero trust and then i understand where my gaps are where i have to mature and where my gaps are and next what we're doing is i have five foundational projects and we're putting together our road map for the next few years what does our phase one look like what where do we want to be after phase one phase two phase three and onward and of course with m22-09 there are some things that we have to specifically do so where do those fit into my road map as well because those are definite things that i have to do because omb is telling us to do it but still it doesn't cover all of zero trust so that roadmap is going to be very important but doing that inventory up front understanding what your capabilities possibly are because i'm a non-for-profit um you know i have to deal with the budget i have but i want to make the most of my investments so that's why i do that inventory first and foremost that was one of my first things is that um is that phased approach going to meet expectations around timeline for hhs that's a good question um because i'll that will be kind of a tbd until i kind of get a little bit more i got to kind of uncover some of the maturity it's kind of a self-assessment but you know it's like peeling back an onion there's so much to this there's so much integration that we need to do but you know my thing is and i tell people is like and i said this the other day in one of my meetings if i take one step forward that's better than taking no steps at all so if i can get 10 percent forward i'm i'm making progress um like i said we're all going to be in we're not get it's not going to be a one size fits all we're not all going to look the same at the end but we have to go back to what are the true concepts when john kinderbad came up with this when he worked at forrester who's the grandfather of zero trust um go back to those concepts just like i always reference back to the osi model still you know it's kind of going back to that zero trust 101 what am i trying to accomplish at the end of the day why am i doing this and understanding that um you can get kind of diluted with the with the the technology and the the you know the buzzword and everything but you got to go back to the ground truth of what is important to you and not just focus on the technology but focus on what your risk tolerances are focus on what your those thresholds need to be and what type of actions you want to take and do a crawl walk run approach right don't go implementing first day and start enforcing it understand if i did this if this happened if i did this what does that look like and then of course move towards implementation at that point yeah so just for the audience i've seen jerry's approach to xero trust and it is one of the most practical and uh in-depth approaches that i've seen um especially in the private sector so i think it's that's that's why we're talking right now because i think it's i think it's amazing but i you know it makes me ask you the question have you ever seen a zero trust deployment that meets the essence of xero trust ever so given that you haven't do you feel that this executive order mandated by the government is practical for agencies to adhere to in adopting xero trust i think so but i think there's still a lot of education of what it really means i talk to a lot of people a lot of people are still asking where do i get started um there are some definite things that we're being asked to do in the memo but there's still a lot to do around zero trust um so with that you know i think it's practical i think it makes sense when you look at the concepts or concepts that we've been talking about forever you know privilege account management um least privilege um you know data segmentation network segmentation these are all concepts but what are we doing we're not doing them in the silo it's not just the identity management team go do your thing in your silo the network team go do your thing in your silo endpoint people do your thing and yourself know this all has to work together because i have to have that telemetry from all these different factors to make decisions and and one of the other things is is is is yeah it's double is one of the other things um i would i would say and um really quickly is this is jerry's opinion is as a federal government we've been very compliance focused right because of fism and things like that and we what do we do is we categorize a system and system has a boundary and based off the categorize that system is with the controls that we put in place but one example i use is okay one control says i need to provide authentication okay username and password i was compliant but i don't think one person i hope would raise their hand if i asked was i effective we all know username and passwords are not very effective so there's a big difference between effectiveness and compliance so i think we need to move and i think that's kind of what the executive order is pushing us towards i mean the way it's titled kind of says it right is we got to be more effective and i think that's where you know mi ai ml are going to be very important in helping with automation because we can't rely on humans and i think that um driving forward how do we measure that effectiveness blue teams purple teams red teams things like that that's what we got to get to measure how do we better measure effectiveness at the end of the day so moving away from cyber security as a checklist to actual practical effectiveness to help prevent against cyber attack and do you feel that the approach that's been taken thus far or that's been mandated will result in better protection against cyber attacks for government agencies yes um one of the things i like to say is if you're an x-files fan of course you know trust no one and you know a lot of people talk about the insider threat well you know with a true zero trust environment insider outsider i'm gonna proof you to who you are i'm gonna if what telemetry do i have with the device you're using if it's a byod device all right i might know model and ios and i can block you based off that but you know i got limited telemetry so my risk is a little is a little more but definitely i think you know it's very important to understand that you got to understand the factors and what's important to you and what how you measure those factors that methodology is is very important i think than just deploying a bunch of tools jerry it's it's interesting to see where this quest for xero trust will take us but i have no doubt that the consistency that you and others in the government are driving for to meet a zero trust strategy will help protect us against cyber attack and so i just want to thank you for your time today it is almost impossible to unpack a topic like xero trust in 20 minutes i think you did a great job so i want to thank you very much and for your efforts in helping protect us thank you [Music]
https://www.youtube.com/watch?v=9VS9Yb5pWl4