Zero Trust People
Last updated on
Purpose
Section titled “Purpose”Zero Trust People ensures that every human access path is explicitly authenticated, authorized, and attributable.
Control objectives
Section titled “Control objectives”- Identity-first access decisions: Authorization is based on verified identity, context, and policy.
- Strong authentication baseline: Privileged and sensitive operations require robust authentication mechanisms.
- Least-privilege role design: Permissions are scoped to tasks and responsibilities.
- Operational accountability: Access actions are attributable and reviewable.
Design recommendations
Section titled “Design recommendations”- Federate enterprise identities: Integrate central identity life cycle and policy enforcement.
- Define role architecture early: Separate platform, security, and application responsibilities.
- Control privileged access: Introduce approval workflows, temporary elevation, and emergency access process.
- Review access continuously: Run periodic entitlement validation and remove stale permissions.
Implementation checkpoints
Section titled “Implementation checkpoints”- Identity integration baseline: Federation setup, trust boundaries, and life cycle ownership documented.
- Role and permission model: Standard and custom role patterns with separation-of-duties controls.
- Privileged access runbook: Elevation, approval, and emergency procedures with audit evidence.
- Access review cadence: Defined governance rhythm for recurring entitlement and exception reviews.
STACKIT references
Section titled “STACKIT references”- Access and Identity: Documentation
- STACKIT IDP: Documentation
- Roles and Permissions: Documentation
- Service Accounts: Documentation
Anti-patterns to avoid
Section titled “Anti-patterns to avoid”- Shared admin identities: Privileged actions cannot be attributed to individuals.
- Role sprawl without governance: Permissions accumulate without periodic validation.
- Permanent elevation: Temporary high-privilege access is never revoked.