Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Zero Trust vs. SASE - Here’s what you need to know

By Derrick Johnson
cyber-security-shield-freepik
July 23, 2021

Zero Trust and SASE have become top of mind for many organizations globally in the past year as business models changed overnight to accommodate a remote workforce, bringing an expanded attack surface. Zero Trust is an enterprise-wide strategy to eliminate risk to the business, whereas SASE provides guidance for vendors to design effective security solutions for the future. While SASE outlines what a solution should have to provide secure access at the edge, other Zero Trust requirements on effective monitoring of threats to the business, continuous maintenance of the environment, and aligning solutions to governance and compliance requirements go beyond any single technical solution.  

While organizations continue to seek implementation of both, they must understand their similarities and most importantly, how they reinforce each other. When reading Gartner’s research on SASE, businesses may think implementing SASE will also implement Zero Trust. This is not a complete approach and it takes multiple initiatives for organizations to properly implement each. Here we’ll discuss these similarities and additional initiatives for successful implementation.

 

The alignment and significance of identity

Because Zero Trust eliminates trust from all access attempts, one may think that identity doesn’t play a role in any Zero Trust strategy. To gain confidence in the communications, and provide access to the appropriate data set, trust algorithms must have access to historical data stores and identity engines. SASE requires identity to drive policy changes based on access requirements. For example, an IoT device accessing a cloud resource versus a business user accessing a private banking application require different levels of identity. In all access cases, knowing who is accessing what requires that the ‘who’ and ‘what’ be identified. As Gartner states: “The identity of a user/device/service is one of the most significant pieces of context that can be factored into the policy that is applied.” They then mention other sources of context that should be evaluated, such as the location of the identity, time of day, risk/trust level, and data/application sensitivity being accessed, which align perfectly with a Zero Trust strategy.

 

Shared principles of Zero Trust Network Access (ZTNA)

ZTNA focuses on providing whitelisting capability for access to services. This is undoubtedly why it is considered one of the core components of SASE. Zero Trust is based on a set of principles or tenets. One of these tenets is that all network flows are authenticated before being processed, and that access is determined by dynamic policy. Another tenet requires authentication and encryption applied to all communications independent of location and that security must be performed at the application layer closest to the asset. These alone are foundational to ZTNA. ZTNA secures access to services at the application layer (layer 7), rather than a complete network, like traditional remote access VPN implementations. Therefore, it provides for the means to only give authorized and authenticated users access to approved applications.

 

Dynamic policies and context-aware trust levels

A tenet of Zero Trust is that access is determined by dynamic policy. Another tenet of Zero Trust is that technology is utilized for automation in support of user/asset access and other policy decisions. This monitoring of user and device behaviors along with automation that drives policy changes is an important part of SASE. Gartner writes that emerging leaders in SASE will embrace a strategic approach to ensure their solution monitors sessions continuously, analyzing for risk levels referencing user entity behavior analytics (UEBA) capabilities, and are “capable of adaptive responses as a user’s behavior is analyzed and subsequent risk increases, or as a device’s trust decreases.” Gartner stops short of detailing what should be done to establish trust and how trust levels should be scored, but they do document that the trust level should be context-aware, which is a recommended approach of Zero Trust.

 

Satisfying the need for a trust and risk engine

Core components of SASE include SD-WAN, secure web gateway (SWG), ZTNA, firewall-as-a-service and cloud application security broker (CASB). One thing that often becomes overlooked is that a SASE solution needs to have the ability to identify sensitive data, and encrypt and decrypt content with continuous monitoring for risk and trust levels. Zero Trust eliminates trust from all network communications and seeks to gain confidence that the communications are legitimate. This level of confidence is applied using trust levels and scoring techniques. Therefore, the implementation of a trust/risk engine that applies contextual scoring capabilities is crucial in a Zero Trust Authorization Core, and SASE provides a means to accomplish this through core component technology.

Because SASE is essentially built upon principles of Zero Trust, Zero Trust is a key cornerstone to SASE. As a result, strategies behind each will continuously overlap, but be mindful that SASE cannot be seen solely as the fast-lane approach to implementing Zero Trust and will require multiple strategies for complete implementation.

KEYWORDS: cyber security risk management security management zero trust

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Derrick Johnson is the National Practice Director for Cyber Operations at AT&T Cybersecurity Consulting.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Security Leadership and Management
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Logical Security
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Technologies & Solutions
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Red laptop

Cybersecurity leaders discuss Oracle’s second recent hack

Pills spilled

More than 20,000 sensitive medical records exposed

Coding on screen

Research reveals mass scanning and exploitation campaigns

Laptop in darkness

Verizon 2025 Data Breach Investigations Report shows rise in cyberattacks

Computer with binary code hovering nearby

Cyberattacks Targeting US Increased by 136%

2025 Security Benchmark banner

Events

May 22, 2025

Proactive Crisis Communication

Crisis doesn't wait for the right time - it strikes when least expected. Is your team prepared to communicate clearly and effectively when it matters most?

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Growing and Gaining

    Want to Avoid Being Scapegoated For the Next Breach? You Need Total Trust Alongside Zero Trust

    See More
  • cyber web freepik

    What you need to know about the deep and dark web

    See More
  • cyberinsurance

    Cyber Liability Insurance: What You Need to Know

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing