- सीआईएसओ नेतृत्व वाली सुरक्षा एवं शासन/
- सुरक्षा विश्लेषण एवं तकनीकी सलाह/
- जीरो ट्रस्ट कार्यान्वयन: टिकने वाले छोटे कदमों से शुरुआत करें/
जीरो ट्रस्ट कार्यान्वयन: टिकने वाले छोटे कदमों से शुरुआत करें
विषय सूची
Zero trust की marketing में एक दिक्कत है। यह term platform pitches और multi-year transformation programs के साथ आती है, जिससे यह impression बनता है कि zero trust adopt करने का मतलब है पूरी identity, network और endpoint estate को एक ही heroic effort में बदल देना। इस तरह कोशिश करने वाले लगभग हर संगठन के प्रोग्राम अटक जाते हैं: प्रोजेक्ट fund करने के लिए बहुत बड़ा, चलाने के लिए बहुत disruptive, और steering committee में चुपचाप मर जाता है।
जो संगठन वास्तव में वहां पहुंचते हैं, वे कुछ कम glamorous करते हैं। वे zero trust architecture (ZTA) को product purchase नहीं, travel direction मानते हैं, और ऐसे छोटे, consistent कदमों में उसकी ओर बढ़ते हैं जिनमें से हर कदम standalone value देता है। लगभग हर environment में उनमें से पहला कदम एक ही है: वे legacy access protocols हटाते हैं जो चुपचाप आपके हर modern control को खोखला कर रहे होते हैं।
Zero trust असल में क्या मांगता है #
Branding हटाकर core idea simple है: access देना बंद करें इस आधार पर कि request कहां से आई है, और शुरू करें इस आधार पर कि request क्या है और यह कौन कर रहा है, हर बार verified.
Traditional security network interior पर भरोसा करती थी। Perimeter के अंदर मतलब trusted था, इसलिए corporate LAN पर, या बाद में VPN पर, laptop बहुत कुछ minimal re-checking के साथ छू सकता था। Zero trust वह assumption उलट देता है:
- Explicitly verify. हर request identity, device health और context से authenticate और authorise होती है, network location चाहे जो भी हो।
- Least privilege. Users और workloads को न्यूनतम access मिलता है, जहां संभव हो time-scoped.
- Assume breach. Design ऐसे करें जैसे attacker पहले से अंदर है, और किसी single compromise से खुलने वाली चीज़ों को सीमित करें।
आखिरी principle ठीक इसी बात से जुड़ता है कि legacy protocols natural first target क्यों हैं।
कदम एक: Legacy protocols को घर से निकालें #
Legacy access protocols anti-zero-trust हैं। वे modern identity thinking से पहले के हैं, और उनकी assumptions ऐसी हैं जिन्हें कोई नया tooling fix नहीं कर सकता:
- SMBv1 और unpatched file-sharing dialects, decades पुराने और neglect से अब भी enabled, जिनका इस्तेमाल attackers entry और lateral movement दोनों के लिए करते हैं।
- NTLMv1 और अन्य weak authentication schemes, जो modern verification support नहीं करते और routinely relayed या cracked हो जाते हैं।
- Telnet और unencrypted FTP, उन networks में credentials cleartext में भेजते हुए जिन्हें आप segmented कहते हैं।
- HTTP basic authentication और unsigned LDAP binds, reusable passwords उन लोगों को expose करते हुए जो traffic observe करने की position में हैं।
- Legacy mail retrieval protocols (unencrypted POP3/IMAP), वह MFA bypass करते हुए जो आप बाकी हर जगह enforce करते हैं।
इनमें से हर एक एक standing invitation है जो कहती है: 1990s के credentials लेकर आओ, हम इन्हें valid मानेंगे। जब तक ये enabled हैं, ये identity checks, device posture checks और conditional access policies के चारों ओर shortcuts बने रहते हैं। ऐसे protocols पर जिनकी पूरी design location-based trust मानती है, आप zero trust architecture build नहीं कर सकते।
Removal वह rare security project भी है जिसका payoff near-immediate है और cost low. ज़्यादातर environments logging के ज़रिए, guesswork से नहीं, पाते हैं कि हर legacy protocol पर systems या workflows की एक छोटी संख्या depend करती है: पुराना printer fleet, किसी supplier का integration, कोई भूला हुआ application. हर dependency का एक छोटा remediation plan बनता है; बाकी सब switch off हो जाता है। Focus के एक quarter में typically exposure का majority खत्म हो जाता है।
फिर बाहर की ओर consistently upgrade करें #
Legacy floor clear होने के बाद बचा सफर overlapping upgrades की sequence है। इनमें से किसी को big bang नहीं चाहिए, और हर एक अगले को आसान बनाता है:
protocols] --> B[MFA everywhere:
users & admins] B --> C[Identity-based access:
replace implicit trust] C --> D[Device posture &
conditional access] D --> E[Per-application micro-segmentation] style B stroke:#10B981,stroke-width:2px style E stroke:#0EA5E9,stroke-width:2px
- Pehle MFA coverage, especially privileged accounts. Sequence में यह highest value-per-dollar control है, और identity foundation establish करता है जिस पर बाकी सब बनता है। Administrators के लिए जहां feasible हो phishing-resistant methods.
- Implicit network trust को explicit grants से बदलें। Remote access को flat VPNs से per-application access की ओर ले जाएं जो identity द्वारा brokered हो। हर migrated application stolen laptop का blast radius सिकोड़ती है।
- Decisions में device health जोड़ें। Access identity से flow करने लगे, तो sensitive applications के लिए managed, patched devices require करें। Unhealthy devices को production data नहीं, quarantined paths मिलती हैं।
- Workloads progressively micro-segment करें। Sabse critical services से शुरू करें: payment systems, domain infrastructure, sensitive data stores. उनके callers explicitly allow-list करें। यह east-west traffic पर applied zero trust है, और इस blog पर पहले discussed segmentation discipline के साथ compound होता है।
- Instrument और iterate करें। हर access decision log करें, denials को false positives के लिए review करें, और scope उस cadence पर expand करें जिसे आपकी teams absorb कर सकें।
Consistency क्यों speed को हराती है #
Zero trust programs का failure mode गलत technology चुनना नहीं; enthusiasm से शुरू करके बीच में रुक जाना है। Half-deployed architecture अक्सर none से भी बुरी होती है: दो access models parallel में चलने का मतलब maintain करने के दो rules sets, और users उसमें से जो ज्यादा झंझट वाला है, उसके around route कर लेते हैं।
Consistent rollout इसलिए जीतता है:
- हर phase usable पर खत्म होता है। Users एक समय में एक change experience करते हैं, support channels तैयार, migration wall की जगह।
- Security gains जल्दी आते हैं और compound होते हैं। Legacy protocols हटाने का payoff तुरंत है; MFA का भी। आप कभी distant finish line का wait करते हुए unbuilt risk hold नहीं करते।
- Budget reality के contact में survive करता है। छोटे funded phases finance review बार-बार pass करते हैं; एक विशाल program आमतौर पर एक बार pass करता है और फिर cut हो जाता है।
- आपकी architecture knowledge इसके साथ बढ़ती है। Micro-segmentation तक पहुंचते-पहुंचते आपकी team identity upgrades और conditional access से गुजर चुकी होती है और अपने environment के real traffic patterns जानती है।
Mid-sized organisations के लिए realistic timeline ऐसा दिखता है: legacy protocol removal एक-दो quarters में, universal MFA उसी के साथ, per-application access अगले दो-तीन quarters में, और progressive workload segmentation standing practice की तरह चलती रहती है। दो साल बाद, कभी “transformation” run किए बिना, आप ऊपर देखते हैं और पाते हैं कि आप उसे operate कर रहे हैं।
हमारा Configuration & Architecture Assessment आज आपके environment में छिपे legacy protocols और implicit-trust paths identify करता है, और हमारी vCISO advisory rollout को ऐसे fundable phases में sequence करती है जिन्हें आपकी team sustain कर सके। या Engineering & Scoping Session schedule करें और step one से शुरू करें।