CMS’s approach to zero trust is structured around maintaining security at four layers: device, network, application and data. One of the most far-reaching zero-trust initiatives being deployed by CMS is an enterprise identity, credential and access management program that will consolidate disparate identity systems in use across the agency into a central repository.
“Being able to federate ICAM services is a big benefit of zero trust,” says Tim Morrow, situational awareness technical manager in the CERT Division of the Software Engineering Institute at Carnegie Mellon University.
“Cloud providers typically have mechanisms where you can tie in Amazon Web Services’ or Google’s version of identity and access management. You also have identity access tied into specific applications. It’s a real challenge to integrate these all together and have a consistent picture, because it gets to be very large and convoluted. But an organization’s focus on identity capabilities and services is an important step in its zero-trust journey.”
Zero Trust on Multiple Fronts
In addition to a range of identity-focused initiatives, CMS is also implementing several other zero-trust solutions, including endpoint detection and response (EDR) and network security improvements.
“We are now centralizing data logging in our security incident and event management tools,” Zarriello says. “This gives us consistent threat analysis across all ecosystems. It’s no longer a disparate, siloed approach where different organizations have different data volume tools and are each doing their own threat analysis. We’ve effectively centralized that threat analysis from a volume perspective.”
“One thing that is often overlooked with zero trust is that it can bring a significant reduction in the volume of unexpected log and network activity that needs to be triaged and investigated,” says Jason Garbis, co-chair of the Zero Trust Working Group for the Cloud Security Alliance. “When access shifts to a ‘default deny, explicit allow’ model, this substantially reduces the amount of access that needs to be evaluated. As a result, the operations team benefits by having more time available to perform those investigations that are truly necessary.”
READ MORE: Why does agentic AI make zero trust more important than ever?
CMS’s zero-trust efforts have not been without challenges. One particularly sticky problem was how to manage network access for the numerous internal and partner developers working on projects for CMS. Zero trust does not allow the kind of wide-open network access that developers traditionally were given. A zero-trust approach means developers get access only to specific applications or specific segments. CMS turned to Zscaler to solve the problem.
“Developers can no longer spin up an environment in the cloud, assign an IP address and just have access to whatever else is within that subnet,” says Zarriello. “There have to be specific actions in order to add access or add permissions to that asset under our zero-trust networking model. This has resulted in more operational oversight and more team members required to effectuate access for developers.”
