JerryMungo
Honorary Master
- Joined
- Jul 18, 2008
- Messages
- 37,567
- Reaction score
- 6,324
.
Last edited:
South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
I wanted to start a ZTNA on a budget thread to list good approaches and apps that can be used to implement the BeyondCorp model - preferably open source / free / low cost.
I have nothing to kick start this with other than a useful curated list of ZTNA resources from pomerium on Github:
![]()
GitHub - pomerium/awesome-zero-trust: A curated collection of awesome resources for the zero-trust security model.
A curated collection of awesome resources for the zero-trust security model. - pomerium/awesome-zero-trustgithub.com
I'll try keeping the OP updated as this develops and list recommended products and approaches here.
Any tools you've used and want to share?
Go!
That is a good explanation. You still need to have inherent secure servers regardless. Twenty users on a server with no 2FA and all using the same password is a brainfart regardless of ZTN.It depends on the size of the organization and their infrastructure.
What I am finding is that we are turning a fair amount of "offices" into internet cafes essentially.
Even if they have infrastructure in the network, it becomes completely isolated and inaccessible except through the same mechanisms as their cloud infrastructure or other infrastructure.
For example something like Netskopes NPA builds a private cloud where you publish everything to this. Access to this private cloud is only via certain mechanisms and is not exposed at all. You can turn your public cloud into a private cloud by cutting it off to the internet and publishing it.
With the office, you only access whatever you need via this private cloud as well.
There are other methods of zero trust which also utilizes dynamic evaluation to change security rules and access based on the evaluation criteria in a similar way to Ciscos TrustSec model (which was actually a really good concept for when it was released) traffic gets tagged and then access and privileges are adjusted accordingly