Skip to main content
Guidance

Zero Trust

How to understand, apply and evolve Zero Trust to protect your organisation’s systems, data and users.

Page 8 of 18

4. Use policies to authorise requests

Each request for data or services should be authorised against a policy.

Example - access authorised by policy

Here is a simple theoretical example of a user accessing a service or corporate data, with a policy authorising the request. A more in depth example, expanding on the use of signals in the authorisation process, can be found below in Use multiple signals to make access decisions.

  1. A user makes a connection to a policy enforcement point, which will mediate their connection to the service or data requested.
  2. The policy enforcement point will query the policy engine for an access decision. The policy engine will evaluate the request against an access policy before suppling an access decision to the enforcement point.
  3. If the access request is accepted by the policy engine, the request is allowed by the policy enforcement point. If it's rejected by the policy engine then the connection is dropped.
  4. The access decision is being continually evaluated in real time. A change in security posture may entail termination of the connection, or re-authentication.

Diagram shows example explained in this section

How you achieve the use of polices to authorise requests depends on the of zero trust technologies you deploy. For example, zero trust using managed cloud services will be different to an on-premises network.

In some approaches, the names and terminology used may be slightly different to our example above.




Example - evaluating signals to a policy engine

The diagram below describes a theoretical example of how a number of signals are evaluated by a policy engine. Signals and user access (via a policy enforcement point) are continually evaluated by the policy engine.

Depending on your implementation of zero trust and the type of signals used, the details may change, but the principle illustrated here should be the same.




Published

Reviewed

Version

1.1