From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Defining subject-object relationships

Defining subject-object relationships

- Another key aspect of zero trust is always understanding the relationship between the user or the subject, and the object or the resource object. So that's going to involve asset identification and management. Physical and virtual/software/logical assets. Asset identification involves ensuring that all of our assets, devices, applications, data services, are accurately identified and cataloged. This helps in understanding what needs to be protected, and how it interacts with other components, for example, in your network. Asset management entails continuously managing and monitoring these assets to ensure they're secure and compliant with organizational policies. If you were to look, for example, at let's say Google BeyondCorp, which is one of their zero trust initiatives, they have a robust inventory of all of their assets, and also the state, machine, and posture of all of the assets in a Google site, for example, tracking asset configurations, knowing about all of the updates…

Contents