Free Agentic AI Workshop Map your footprint, identify your highest-risk gaps, and leave with a leadership-ready summary. Book a Workshop→
Start assessment

Neighborhood Notes: Conversation about the CISA Zero Trust Maturity Model

November 1, 2024 · Numberline Marketing

Thanks again to those of you who were able to join us for our recent peer Zero Trust practitioner group, The Neighborhood. In this session, we dove into an in-depth discussion about the CISA Zero Trust Maturity Model. We use this model a lot – in fact, it’s the basis for the maturity assessments we do as part of our enterprise Zero Trust strategy work, so we’re deeply familiar with its strengths and weaknesses, and how it needs to be adapted (more on that later).

There was general agreement within the group that the CISA model has become the de facto standard for the industry; none of the participants were using either the US Department of Defense maturity model, or models from any of the security vendors. The DoD model was generally assessed as being more complex than CISA, while the vendor models weren’t as comprehensive as CISA’s, and were (of course) not vendor-neutral.

The real test of any model, of course, is seeing how well it can apply to a real-world enterprise environment. Our consensus is that the CISA model is good, but needs some improvements. 

First, there are definitely some missing functions that need to be added, in order to better capture the reality of enterprise environments. For example, the Identity pillar includes a User Authentication function, but has no place to evaluate enterprise maturity for Non-Person Entities (NPEs) such as service accounts or machine identities. In many enterprises, these NPEs constitute a significant part of the environment, and technologies and processes that are distinct from user authentication.

Second, there are some functions that need to be clarified, because their maturity progression isn’t always clearly aligned with their definition. For example, if you look at how its function maturity levels are defined, the Network Resilience function is really closer in spirit to a Network Capacity Management function. 

These are just two examples of what we discussed. Teaser – the Numberline team has been working on a more comprehensive set of enhancements to the CISA Zero Trust Maturity Model. Stay tuned for some exciting announcements in the coming weeks.

Interested in joining future discussion sessions? If you’re an enterprise security professional, please visit our Neighborhood page for more information and registration details for upcoming sessions. As always, there is no charge to participate – your only investment is your time.

Discover more from Numberline Security

Subscribe now to keep reading and get access to the full archive.

Continue reading