{"id":6856,"date":"2023-09-28T12:01:16","date_gmt":"2023-09-28T16:01:16","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=6856"},"modified":"2023-09-28T12:05:02","modified_gmt":"2023-09-28T16:05:02","slug":"dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/","title":{"rendered":"Dynamic Authorization Fulfills the Promise of Zero-Trust Architecture"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-6857\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture.jpg\" alt=\"\" width=\"800\" height=\"400\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture-300x150.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture-768x384.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><em><strong>Solutions Review\u2019s\u00a0<a class=\"fui-Link ___1idfs5o f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1hu3pq6 f11qmguv f19f4twv f1tyq0we f1g0x7ka fhxju0i f1qch9an f1cnd47f fqv5qza f1vmzxwi f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh ftqa4ok f2hkw1w fhgqx19 f1olyrje f1p93eir f1h8hb77 f1x7u7e9 f10aw75t fsle3fq f17ae5zn\" title=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" href=\"https:\/\/solutionsreview.com\/solutions-review-contributor-guidelines\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Link Contributed Content Series\"><u>Contributed Content Series<\/u><\/a> is a collection of contributed articles written by thought leaders in enterprise software categories. Gal Helemski of <a href=\"https:\/\/www.plainid.com\/\" target=\"_blank\" rel=\"noopener\">PlainID<\/a> examines how Dynamic Authorization fulfills the promise initially made by zero-trust architecture.<\/strong><\/em><\/p>\n<p>Cybersecurity is a tough business for many reasons, foremost among them the fact that nine times out of ten, your most paranoid fears turn out not to be paranoid enough. Whatever worst-case scenario you might be worrying over, you can be sure a hacker is hard at work bringing something even worse to life.<\/p>\n<p>It&#8217;s for this very reason that, for the last decade-plus, the reigning defensive philosophy of the cybersecurity world has been zero-trust architecture. Its guiding principle is that no one can be automatically trusted. Everyone is a potential bad actor until proven otherwise. The mass adoption of these principles over the last decade has been a highly positive development. The proliferation of network access control and advanced authentication tools has been hugely beneficial. But there are indications that most companies haven&#8217;t taken things far enough in securing their assets\u2014 especially when it comes to entry points that aren&#8217;t network-centric. In fact, 40 percent of respondents to a recent survey said they&#8217;re still using homegrown, customized solutions to authorize user identities, leaving perilous gaps in their security infrastructure.<\/p>\n<p>The only response to our current threat environment \u2014 in which ransomware attacks are continually on the rise \u2014 is an unflagging investment in true zero-trust network architecture. Only dynamic, granular, ultra-responsive authorization can truly keep businesses and consumers safe.<\/p>\n<br \/>Widget not in any sidebars<br \/>\n<h2><strong>Dynamic Authorization Fulfills the Promise of Zero-Trust Architecture<\/strong><\/h2>\n<hr \/>\n<h3><strong>What Current Zero-Trust Gets Wrong\u00a0<\/strong><\/h3>\n<p>Again, we should applaud businesses for their investments in zero-trust architecture. In general, authentication processes circa 2010 were unbelievably crude compared to the more sophisticated methods businesses are deploying today. But that doesn&#8217;t mean we can just rest on our laurels, especially when bad actors are waiting to take advantage of the slightest slip-up.<\/p>\n<p>The fact is that zero-trust architecture, as currently practiced, has serious problems that put us all at risk. Per the National Institute of Standards and Technology (NIST) report on zero trust architecture, zero trust is not just about things like network access, assessing risk, detecting intrusions, etc. Current zero-access tools do a relatively good job of taking care of things like that, but they&#8217;re only part of the story. To meet the true definition of zero trust, per the NIST report, a given company&#8217;s architecture also requires dynamic decisions and authorization, the ability to grant access on a per-session basis, and the ability to strictly enforce these decisions before access is granted. And when it comes to those components of the zero-trust architecture, most businesses still have a long way to go.<\/p>\n<p>In a nutshell, the reason the above-listed specifications matter is that\u2014in the decade since zero trust thinking rose to prominence, and especially in the years since the pandemic\u2014the digital enterprise has grown ever more complex. Peer into the inner workings of any organization, and you&#8217;ll find hundreds of interconnected applications, countless systems, on-premises and remote multi-cloud storage, and thousands of continually shifting roles belonging not just to employees but also to partners, contractors, customers, and more.<\/p>\n<p>In an environment like this, every attempted interaction with your business, no matter how small, needs to be treated as its own potential threat event and evaluated accordingly in real-time. Static authorization approaches like role-based access control (RBAC) can only take you so far here\u2014 they&#8217;re a blunt hammer when what&#8217;s needed is something much more sophisticated.<\/p>\n<h3><strong>Why Dynamic Authorization is the Answer <\/strong><\/h3>\n<p>Suppose traditional RBAC functions much like an old-fashioned keycard. You plug in your user information, and if you&#8217;ve been preassigned access, you&#8217;re waved in. Dynamic authorization takes in a much more complex set of variables&#8211; not just for the network but also for application resources, data assets, and any other assets. Thus, for the first time making NIST&#8217;s definition of zero trust architecture an attainable reality for most businesses.<\/p>\n<p>Where RBAC is 2D, dynamic authorization, like policy-based access control (PBAC), is 4D, considering not just who but also what and when before making an access decision. It evaluates not just the person making the request but also what that person is trying to access, what that access enables them to do within the system, and \u2014taking a bird&#8217;s eye view\u2014 the established system-wide conditions for that access, and only then does it come to a final access decision. This hugely complex process\u2014which, in practice, is completed in seconds\u2014is repeated every single time someone attempts to make contact with your environment. The key word here is granularity: making a decision with the highest levels of granularity possible in order to keep your company (and your customers) safe.<\/p>\n<p>Again, this technology exists right now, but far too few companies are taking advantage of it. According to the survey referenced earlier, only 31 percent of respondents said they have sufficient visibility and control over authorization policies intended to enforce appropriate data access. Dynamic authorization can provide that visibility and more\u2014 finally fulfilling the promise of zero trust architecture and keeping their assets out of the hands of bad actors.<\/p>\n<br \/>Widget not in any sidebars<br \/>\n","protected":false},"excerpt":{"rendered":"<p>Solutions Review\u2019s\u00a0Contributed Content Series is a collection of contributed articles written by thought leaders in enterprise software categories. Gal Helemski of PlainID examines how Dynamic Authorization fulfills the promise initially made by zero-trust architecture. Cybersecurity is a tough business for many reasons, foremost among them the fact that nine times out of ten, your most [&hellip;]<\/p>\n","protected":false},"author":920,"featured_media":6857,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,1],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Dynamic Authorization Fulfills the Promise of Zero-Trust Architecture<\/title>\n<meta name=\"description\" content=\"Gal Helemski of PlainID examines how Dynamic Authorization fulfills the promise initially made by zero-trust architecture.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Gal Helemski\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/\",\"name\":\"Dynamic Authorization Fulfills the Promise of Zero-Trust Architecture\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture.jpg\",\"datePublished\":\"2023-09-28T16:01:16+00:00\",\"dateModified\":\"2023-09-28T16:05:02+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/ad0644fc790ed291d9eb6675c803273a\"},\"description\":\"Gal Helemski of PlainID examines how Dynamic Authorization fulfills the promise initially made by zero-trust architecture.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture.jpg\",\"width\":800,\"height\":400,\"caption\":\"Dynamic Authorization\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Dynamic Authorization Fulfills the Promise of Zero-Trust Architecture\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Identity and Access Management Solutions | Solutions Review\",\"description\":\"Evaluating Enterprise IAM Software, Identity Governance &amp; Access Control Tools.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/ad0644fc790ed291d9eb6675c803273a\",\"name\":\"Gal Helemski\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/085abc7fac91887ef6501a09b02a35ec?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/085abc7fac91887ef6501a09b02a35ec?s=96&d=mm&r=g\",\"caption\":\"Gal Helemski\"},\"description\":\"Gal Helemski is the Co-Founder and CTO\/CPO of PlainID and a highly recognized and acclaimed cybersecurity expert. She plays a key role at PlainID as a strategic leader, visionary, and evangelist while overseeing product development, including leading the product architecture, strategy, and engineering teams. During the last 20+ years, Gal has defined solutions for customers and created and defined project specs, technical documentation, presentations, and training focused on identity and access management. As an early member of the CyberArk team, Gal has been highly influential in the identity space for most of her career. She earned a bachelor of science degree in physics and computer science from Bar-Ilan University after serving six years in the Israeli Defense Force\u2019s prestigious Mamram computing unit.\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/helemski\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Dynamic Authorization Fulfills the Promise of Zero-Trust Architecture","description":"Gal Helemski of PlainID examines how Dynamic Authorization fulfills the promise initially made by zero-trust architecture.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/","twitter_misc":{"Written by":"Gal Helemski","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/","url":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/","name":"Dynamic Authorization Fulfills the Promise of Zero-Trust Architecture","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture.jpg","datePublished":"2023-09-28T16:01:16+00:00","dateModified":"2023-09-28T16:05:02+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/ad0644fc790ed291d9eb6675c803273a"},"description":"Gal Helemski of PlainID examines how Dynamic Authorization fulfills the promise initially made by zero-trust architecture.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2023\/09\/Dynamic-Authorization-Fulfills-the-Promise-of-Zero-Trust-Architecture.jpg","width":800,"height":400,"caption":"Dynamic Authorization"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/dynamic-authorization-fulfills-the-promise-of-zero-trust-architecture\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Dynamic Authorization Fulfills the Promise of Zero-Trust Architecture"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Identity and Access Management Solutions | Solutions Review","description":"Evaluating Enterprise IAM Software, Identity Governance &amp; Access Control Tools.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/ad0644fc790ed291d9eb6675c803273a","name":"Gal Helemski","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/085abc7fac91887ef6501a09b02a35ec?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/085abc7fac91887ef6501a09b02a35ec?s=96&d=mm&r=g","caption":"Gal Helemski"},"description":"Gal Helemski is the Co-Founder and CTO\/CPO of PlainID and a highly recognized and acclaimed cybersecurity expert. She plays a key role at PlainID as a strategic leader, visionary, and evangelist while overseeing product development, including leading the product architecture, strategy, and engineering teams. During the last 20+ years, Gal has defined solutions for customers and created and defined project specs, technical documentation, presentations, and training focused on identity and access management. As an early member of the CyberArk team, Gal has been highly influential in the identity space for most of her career. She earned a bachelor of science degree in physics and computer science from Bar-Ilan University after serving six years in the Israeli Defense Force\u2019s prestigious Mamram computing unit.","url":"https:\/\/solutionsreview.com\/identity-management\/author\/helemski\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/6856"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/920"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=6856"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/6856\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/6857"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=6856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=6856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=6856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}