Certified Information Security Manager (CISM)Information Security ProgramMedium

A CISO is developing an information security architecture for a new product line that will involve significant use of third-party APIs and microservices. The primary concern is ensuring data integrity and confidentiality across disparate trust boundaries. Which architectural principle should the CISO emphasize MOST to achieve this?

  1. ASeparation of Duties
  2. BLeast Privilege
  3. CZero Trust
  4. DDefense in Depth
Show answer & explanation

Correct answer: C. Zero Trust

With significant use of third-party APIs and microservices, traditional perimeter-based security is insufficient. Zero Trust, which mandates verifying every request regardless of origin and assuming no inherent trust, is the most appropriate principle to ensure data integrity and confidentiality across disparate trust boundaries.

Why the other options are wrong

  • A. Separation of Duties is an administrative control, important for internal processes, but not the primary architectural principle for securing data across external API/microservice interactions.
  • B. Least Privilege is a component of Zero Trust, but Zero Trust is the overarching principle for this scenario.
  • D. Defense in Depth is a general strategy, but Zero Trust provides the specific framework for handling multiple untrusted boundaries in a microservices environment.

Zero Trust Architecture

A security model based on the principle that no user or device should be trusted by default, regardless of whether they are inside or outside the network perimeter. All access requests must be verified.

  • Never trust, always verify.
  • Critical for microservices, cloud, and third-party integrations.
  • Focuses on granular access control and continuous authentication.

Memory trick: Trust No Bridge, Verify Every Step, Guard the Data Deep.

More Information Security Program questions