Certified Information Security Manager (CISM)Information Security ProgramHard

An organization is undergoing a digital transformation, rapidly adopting cloud services and agile development methodologies. The CISO recognizes that the traditional, perimeter-focused security architecture is no longer adequate. Which of the following architectural principles should the CISO prioritize to establish a robust security posture in this new environment?

  1. AImplementation of a comprehensive Zero Trust model across all environments.
  2. BOutsourcing all security functions to a Managed Security Service Provider (MSSP).
  3. CReliance on endpoint detection and response (EDR) solutions as the primary control.
  4. DEmphasis on strong network firewalls and intrusion prevention systems at the perimeter.
Show answer & explanation

Correct answer: A. Implementation of a comprehensive Zero Trust model across all environments.

With rapid adoption of cloud services and agile development, the traditional network perimeter dissolves, and trust boundaries become blurred. A Zero Trust model (B) directly addresses this by enforcing 'never trust, always verify' for every user, device, and application, regardless of location. This is crucial for securing dynamic cloud environments and agile workflows where assets are no longer confined to a protected internal network.

Why the other options are wrong

  • B. Outsourcing security functions is an operational decision, not an architectural principle that defines how security itself is integrated and enforced within the new digital transformation context.
  • C. While EDR is a vital component, relying on it as the *primary* control is insufficient; Zero Trust provides a broader architectural principle for securing the entire ecosystem.
  • D. Perimeter-focused controls are insufficient for cloud and agile environments where the perimeter is fluid or non-existent.

Zero Trust Architecture

A security model that assumes no user, device, or application is inherently trustworthy, regardless of its location (inside or outside the network), requiring continuous verification for every access request.

  • 'Never trust, always verify' principle.
  • Crucial for cloud and hybrid environments.
  • Minimizes lateral movement of attackers.

Memory trick: In the cloud, trust no one, verify every single connection, always.

More Information Security Program questions