Hello, Dalí: Surrealism and Zero Trust
Recently, my wife and I visited the Museum of Fine Arts in Boston. While getting our tickets scanned to enter, I asked the guard whether they needed me to provide a PIN also, because, “after all, this is the MFA!” Alas, they just stared at me blankly. So much for my attempt at making a multi-factor authentication joke.
We visited the museum to see an exhibit entitled Dalí: Disruption and Devotion, and the curators did a great job of showing Dalí’s paintings alongside historical artwork, which he so often referenced in his work. For example, Dalí frequently used elements of paintings by Diego Velázquez, a Spanish artist from the early 1600’s. Clearly, Dalí was a classically trained and historically aware artist, who’d mastered multiple styles of art. He was therefore able to amazingly create new ways of doing things, which synthesized and built on traditions of the past.
The exhibit also illustrated his technical capabilities. By this, I mean his skills at painting incredibly precisely to express his bizarre and surrealist perspective. Numerous of his paintings include double images that act as optical illusions, with detailed elements that when viewed from afar, fuse into another shape. For example, his work “Slave Market with the Disappearing Bust of Voltaire”, which was part of exhibit, shows this as the centerpiece of this painting:

Tying this back to information security, what prompted my thoughts were less his technical skills, and more the way he included references to and built on historical elements of art, leveraging history and best practices in his field. The overall point of the exhibit was to illustrate how he communicated his vision, which while unique and groundbreaking, also built on traditional skills and echoed the past.
In some ways, this is similar to what we’re doing with Zero Trust. Not that we want to give users a surreal experience, but rather to, like Dalí, leverage best practices and proven methods, combining them in a novel and more effective way.
For example, the shift from using RBAC to ABAC to CBAC illustrates a transition in approach. While we continue to use roles in ways that are appropriate, newer methods leverage identity attributes, improve supporting identity governance processes, and combine enterprise signals into an overall set of contextual information. This context is drawn from across the enterprise environment, and includes signals that occur at administration time, authentication time, and runtime.
Information security is an art, and it takes a lot of both technical and non-technical scale to execute well. It also takes a lot of organizational awareness, as well as the ability to communicate across the entire organization, especially with non-technical and non-security users. Fortunately, Zero Trust as a strategy and set of supporting processes provides us with a framework to be effective information security artists.
As we approach the holiday season, be sure to take some time away from Infosec to enjoy and appreciate other elements of life. Whether it’s art, music, cooking, exercise, or just spending time with family and friends, please be sure to take care of yourself. Infosec is a challenging role, and we all need a mental break periodically.