In a previous article on the Government Technology Insider, Optiv + ClearShark’s Senior Director of Risk and Information Security, Mark Modisette, shared how government agencies could turn Zero Trust from a buzzword into a proven line of defense against cyber-attacks.

In part two of a three-part interview series, Mark returns to GTI to discuss the technologies and solutions that comprise Zero Trust, debunk the common misconceptions around the cybersecurity framework, and share important first steps for Zero Trust adoption.
GovCyberHub (GCH): Knowing that Zero Trust isn’t just a single solution that agencies can purchase and implement, how should federal agencies begin approaching Zero Trust adoption?
Mark Modisette: When it comes to Zero Trust adoption, agencies should begin with security program initiatives, such as business alignment, policies, standards, security architecture, and a well-thought-out security roadmap and align those elements with Zero Trust. Mapping an agency’s current IT and security capabilities to Zero Trust capabilities and activities to achieve the desired outcomes will help organizations take a more deliberate approach to designing Zero Trust use cases and ultimately result in risk reduction.
Taking the time to understand what security capabilities exist and how those capabilities will help move them towards those Zero Trust core principles will save agencies time and money. “Visibility and Analytics”, and “Orchestration and Automation” are key to understanding what is on an agency’s network and how people and machines are behaving. These capabilities will enable organizations to have situational awareness and add the option to automate a response, and/or act fast with the intelligence to accelerate a human-based response.
GCH: What different types of solutions and tools are needed for a Zero Trust approach to cybersecurity? What tools should agencies consider as they approach and plan for Zero Trust adoption efforts?
Mark Modisette: The Cybersecurity and Infrastructure Security Agency (CISA) and the U.S. Department of Defense (DoD) have developed reference architectures that outline pillars that are in scope when applying Zero Trust core principles.
The pillars CISA and the DoD have defined are User/Identity, Device, Network and Environment, Applications and Workloads, Data, Automation and Orchestration, and Visibility and Analytics.
At Optiv + ClearShark, we added two pillars to ensure clients are set up for success: Security Program Management and Security Risk Management. While these are considered more like domains than tools, these areas are critical in the development of a Zero Trust approach. Implementing capabilities under these areas – such as solid mission alignment, building strong relationships between mission leaders to help deliver training, and setting expectations when it comes to changes related to a Zero Trust approach – will greatly increase chances for success.
In addition, ensure critical documentation are elevated to include Zero Trust guiding principles and Zero Trust-aligned policies, procedures, and standards. This is also a good time to enhance the agency’s risk management processes, ensure risks have owners, and workflows exist to support a modern risk-based approach. A solid metrics program can also help illuminate gaps and highlight successes.
GCH: For agencies that are getting started, what are the first steps that you would recommend they take toward Zero Trust adoption? Does it start with the implementation of specific security tools, or are there other things that need to be accomplished first?
Mark Modisette: Along with what I previously mentioned regarding an agency’s Security Program Management and Risk Management, another place to start is rationalizing their tools and understanding what features and functionality they already have deployed. They should then look at compatibility between tools and mission components.
Implementing Zero Trust concepts cannot be done without compatibility between tools and the integration of technology. An area where integration is particularly important is Orchestration and Automation. This is where the rubber meets the road. Using the human body as an analogy to describe a Zero Trust approach, think of Orchestration and Automation as the nervous system, Security Program Management/Security Risk Management as the brains, and Visibility and Analytics as the eyes.
The Zero Trust experts in the DoD specifically highlighted opportunities for acceleration in the User, Orchestration and Automation, and in Visibility and Analytics for a reason – these areas are key from a process and technology perspective concerning Zero Trust implementation.
GCH: Are there any mistakes or misconceptions that you see across the government as it relates to Zero Trust?
Mark Modisette: Several things come to mind. First, agencies don’t have to rip and replace to achieve a Zero Trust approach. A review of their current tool landscape is important and will help them determine what they need.
Second, agencies simply cannot buy Zero Trust out of the box. There are too many factors that go into reviewing and understanding what processes or tools will enable Zero Trust adoption.
Third, Zero Trust is not all about technology. People and processes are still integral parts of the Zero Trust movement. There is and will always be a balance between these three important factors.
Last, agencies should beware of, “Shiny object syndrome.” There are plenty of cool tools out there that will help solve problems and reduce risk. Agencies should review their security risk management program and see if they can bring their Zero Trust project and plan initiatives together with reducing their big risks.
GCH: What role can private sector partners play in helping agencies start or advance their Zero Trust adoption journey?
Mark Modisette: Federal agencies should consider partnering with someone who has a history of successfully implementing Zero Trust-enabling technology. A commercial partner may have experienced issues and designed Zero Trust enterprise solutions to solve problems that an agency may not have seen yet.
The relationships that their go-to partners have with vendors may also help benefit clients. The best part is to leave the implementation details to a trusted partner, which will leave their hands free to address the mission.
In the third and final part of our discussion with Mark, we explore some of the steps that agencies can take to cultivate an organizational culture that embraces Zero Trust cybersecurity.