inklap

A CONTEXT-AWARE APPROACH TO ORGANIZING NETWORK SECURITY POLICIES IN A ZERO TRUST ARCHITECTURE

Roman Syrotynskyi · Cybersecurity: Education, Science, Technique · 2025

The relevance of introducing new approaches and practices for organizing and controlling access in network infrastructures is justified by the widening gap between the requirements of modern security standards and the capabilities of network security tools that operate at Layers 3–4 of the OSI model. The paper analyzes security models recommended by contemporary standards and industry best practices for information infrastructures, and explores ways to implement them using available market tools and network access control measures. The methodological basis of the proposed approach combines the Zero Trust principles outlined in NIST SP 800-207, capabilities found in the portfolios of next-generation firewall vendors, and the author’s methodologies and practices for integrating heterogeneous security systems to enrich firewall security policies with network-access context. The approach enables adherence to Zero Trust principles while maintaining operational quality and high performance of the network infrastructure, without exceeding acceptable total cost of operation and ownership of infrastructure resources. Key components and design patterns of the security infrastructure necessar

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً