A CISO is designing an information security architecture for a new product line that will utilize microservices and serverless functions. The existing security architecture primarily relies on perimeter-based controls and centralized identity management. To ensure the new product line's security is aligned with its architectural principles, which of the following is the MOST critical architectural shift the CISO must advocate for?
- AImplementing robust endpoint detection and response (EDR) on all developer workstations.
- BEstablishing a dedicated Security Operations Center (SOC) for the new product line.
- CExtending existing network firewalls to protect cloud-based microservices.
- DShifting to a 'zero trust' model with granular, context-aware access controls for each service.
Show answer & explanationAnswer & explanation
Correct answer: D. Shifting to a 'zero trust' model with granular, context-aware access controls for each service.
Microservices and serverless architectures break down traditional perimeters, making perimeter-based controls less effective. A 'zero trust' model, which assumes no implicit trust and requires verification for every access request, aligns best with the distributed and dynamic nature of these modern architectures by applying granular, context-aware controls directly to each service and function.
Why the other options are wrong
- A. EDR on workstations is important for developer security but doesn't address the fundamental architectural shift required for securing the microservices runtime environment.
- B. A SOC is an operational function. While beneficial, it doesn't represent the fundamental architectural shift needed to secure the underlying microservices and serverless design principles.
- C. Perimeter firewalls are less effective for microservices and serverless, which often have highly distributed and dynamic network boundaries. This is not a critical architectural shift.
Microservices Security Architecture
A security approach designed for distributed microservices environments, emphasizing granular, API-driven security, zero trust principles, and service-level protection over traditional perimeter-based controls.
- Moves security closer to individual services.
- Requires granular access control and API security.
- Perimeter security alone is insufficient.
Memory trick: Microservices demand 'Zero Trust Zones' for every tiny piece.