Putting the whole history together: what does a contemporary cyber security architecture look like?
A combination, structured by the three clauses of the model: define boundaries and zones for the system, a high-quality IAM for the actors, and smart security tools for the actions and the environment.
* Structures for the system, a quality IAM for the actors, smart tools for the actions — combined, not chosen between. *
Working from the model — only good actors, doing good actions, in a desired environment — the combined approach has three workstreams:
1. The cyber system → define structures.
- Define system boundaries, zones or other kinds of segmentation.
- Combine perimeters and micro-perimeters — the large border and the small ones are not alternatives.
- The goal: small sections, based on risk analyses. Not uniform segmentation everywhere, but fine granularity where the risk analysis says it is worth the effort.
2. Good actors → a high-quality IAM system.
- It must be able to cover all requirements: legacy and modern protocols. An identity platform that only speaks modern federation leaves everything old outside, which in practice means an exception that becomes permanent.
- Risk-based access control — the zero trust model: the decision depends on user, device, context and risk, not on a network position.
- Upstream jump hosts, proxies or similar for everything that cannot participate technologically. This is the standard answer for OT and legacy systems: if the system cannot authenticate properly, put something in front of it that can.
3. Good actions and a desired environment → smart security tools.
- Use them to enforce segmentation and boundaries.
- Find suitable technologies — one size does not fit all.
- Combine them with IAM to achieve improved access management, so that the decision about a connection can use both what the traffic is and who is behind it.
The through-line is that each historical era contributed one workable idea, and the modern architecture keeps all of them — perimeters for structure, IAM for actors, system hardening and smart tools for the actions — rather than declaring the older ones obsolete.
Go deeper:
NIST SP 800-207 — Zero Trust Architecture — the tenets and deployment variants in full, including what to do with what cannot participate.