Robert Sirchia, SUSE | DevOps Connect 2022
At DevOps Connect 2022, Robert Sirchia, senior technical evangelist at SUSE, takes a deep dive into what open zero-trust is and its approach to full lifecycle container security.
Transcript
Hello and welcome. My name is Robert sergia. I'm a senior technical evangelist at Susa part of the Sousa Ranch Community.
And today we'll be talking about open zero trust. But before we can talk about what is open zero trust you should level with what is zero trust and Beyond just a catch phrase zero trust is a model of information security that is proactive now. What does that mean?
Well. We want some monitor things the entire life cycle of what we're securing. So proactive zero trust Security will do continuous vulnerability scanning through container images host pods within Docker Oregon kubernetes.
It's continuous compliance scanning because we can do things after the facts in a post-mortem when you're compromised or we can do it as we're going and if we're doing things proactively we have to do this before and during the execution of any type of code or any object within your environment. We also bring in Mission Control to this. We want to make sure that we lock things down effectively.
Where individuals or even devices they cannot do things that we don't want them to do. On that we want to build in Behavior learning zero trust policies and we apply this to multiple layers inside of an organization or kubernetes cluster for that matter. Now we hit we talk about stero trust as Seven Pillars and these Seven Pillars should not be new to anybody.
But we look at the users. We look at their devices or device that come into a particular environment. We look at the networking and environments and then we go deeper within the application and workloads and then the visibility and analytics to what this would look like from there.
Some of the other things that are very familiar for everybody would be the automation orchestration you that ease and then lastly the data. These are the Seven Pillars that when we talk about when we talk zero trust and if you're moving to a zero trust model the security the security should look something like this where we minimize the attack Services we only Out individuals into the network that we trust, but we don't give them. Full access we want to limit their access without so generally when you get you're not the server admin anymore, you're just a user on that and that's by Design.
So we've kind of locked down individuals or items or anything within an environment to only get the access that's needed. We enforce it everything in real time so we can do things after the fact post-mortem, but that doesn't really help us during an attack or being proactive before an attack. So we need to know when it happens and we need to monitor everything as it's in real time.
We also want to be provide continuous visibility and compliance because we can't really know what's going on with the environment unless we're properly reporting that out to other. Systems or to other individuals who understand what's going on with that? And lastly we want to be make it transparent easy to use.
This is where open zero trust comes because what we believe is building something that's a little more open source for that. So what is open zero trust open zero trust is a full life cycle container security platform with specific areas where zero trust controls are enforced. Are in a mission controls containers?
Container firewalls container workload security and all these areas are allowed through particular behaviors that are declarative through a console and automated through crds. Now we talked about making it open is open zero trust is open source, and we're fully transparent with the code. That's executing.
We're fully transparent on a processes that are on how we secure and monitor the security of a particular cluster open sources for full community engagement. So anyone can Grab a pull request. So request new features right there in GitHub and all of this is to make open zero trust a Community Driven project for zero trust security.
com. And I want to thank you for your time.





