Infrastructure Protection – DCS Website
 
 
 
 

  Security Service Edge (SSE)

 
 
Zero Trust Secure Access (ZTSA) – Centralize your digital security management with integrated policies, risk response, and visibility
In today’s ever-connected world, many organizations are transitioning to—or have already adopted—hybrid or remote operations. With the widening of digital attack surfaces comes increased cyber risk, and so the adage of “trust, but verify” is no longer practical. Broad, implicit-trust methods and practices are insufficient for your operations in the face of today’s stealthy, resourceful adversaries and an ever-changing threat landscape. Prioritizing effective verification helps to mitigate your cyber risk.

Harness Trend Vision One™ – Zero Trust Secure Access (ZTSA) to securely connect your users, devices, and applications no matter where they are or what they need to access. With an agile approach to access control, strengthen your protective measures with granular visibility, enhanced security, and continuous risk assessment. Safeguard your users’ journey and engagement with generative AI (GenAI) capabilities driving zero-trust architecture that support your business objectives.

Rethinking trust in your organization
In many organizations, implicit trust is the standard. However, this exposes your business to considerable risk, in which case a single compromised identity could begin to wreak havoc in your environment and move throughout your network.

Much like digital transformation, your path toward zero trust is a journey rather than a solution. There are four important steps that can be taken depending on the highest-priority risk in your organization and current security posture. While more use cases exist, which can be implemented over time as your organization moves towards zero trust architecture, these initial steps include the following:

1. SWG: Securing access to the internet with real-time insights

    • Provides agent and agentless protection for secure web browsing and unsanctioned application access
    • Presents highly contextualized data to Trend Vision One for greater visibility
    • Offers visibility into internet access and browsing to return security and policy control
    • Protects both corporate and bring-your-own (BYO) devices
    • Integrates natively within Trend Vision One
    • Powered by Trend Micro™ Web Reputation Service, Trend™ Research, and ASRM

2. CASB: Secure cloud application access and control

    • Features agent and agentless protection to sanctioned SaaS applications
    • Delivers secure access to SaaS applications, checking for policy violations and security risks
    • Reduces the risk of unauthorized access to data and critical information
    • Monitors application activity through granular cloud application action control
    • Provides continuous risk assessment, powered by ASRM
    • Leverages a simple-to-manage interface within Trend Vision One

3. ZTNA: Secure access to business-critical resources with a modern approach

    • Provides agent and agentless access with detailed control options for easy end-user access to corporate applications and resources
    • Reduces the implicit trust of virtual private networks (VPNs) for greater risk assessment
    • Delivers authenticated and secure just-in-time access to applications and resources for greater protection
    • Reduces the blast area if there is a threat by limiting access to only specific parts of the network
    • Provides continuous risk assessment, powered by ASRM
    • Controls connections to applications and resources with continuous risk assessment dynamically allowing and revoking access as risk profiles change

Instead of granting access to the entire network, as a VPN does, ZTSA provides you with a gateway to specific applications and resources, restricting access to everything within the network that is not being employed. This way, should valid user credentials be stolen, the level of access they will grant to the organization will be limited and contained, effectively reducing the “blast area” of any cyberattack.

4. ZTSA – AI Service Access: Secure the user journey to GenAI services

    • Controls AI application usage by applying continuous risk-based access rules with granular visibility
    • Inspects GenAI services’ prompt and response to help avoid potential data leakage and unpredictable responses
    • Detects prompt injection attacks to mitigate risk of potential manipulation from GenAI services
    • Avoids the private model denial of service threats
    • Delivers secure access to GenAI applications, checking for policy violations and security risks
    • Reduces the risk of unauthorized access to data and critical information
Zscaler Internet Access (ZIA)
Zscaler Internet Access includes a comprehensive suite of AI-powered security and data protection services to help you stop cyberattacks and data loss. As a fully cloud-delivered SaaS solution, you can add new capabilities without any additional hardware or lengthy deployment cycles.

The modules available as part of Zscaler Internet Access are:

  • Cloud Secure Web Gateway (SWG): Deliver a safe, fast web experience that eliminates ransomware, malware, and other advanced attacks with real-time, AI-powered analysis and URL filtering from the only leader in the 2020 Gartner MQ for SWGs.
  • Cloud Access Security Broker (CASB): Secure cloud apps with integrated CASB to protect data, stop threats, and ensure compliance across your SaaS and IaaS environments.
  • Cloud Data Loss Prevention (DLP): Protect data in motion with full inline inspection and advanced measures like exact data match (EDM), optical character recognition (OCR), and machine learning.
  • Zscaler Firewall & cloud IPS: Extend industry- leading protection to all ports and protocols and replace edge and branch firewalls with a cloud native platform.
  • Zscaler Sandbox: Stop never-before-seen and elusive malware across web and file transfer protocols with AI-driven quarantine, sharing consistent and global protection across all users in real time.
  • AI-Powered Cloud Browser Isolation: Make web-based attacks obsolete and prevent data loss by creating a virtual air gap between users, the web, and SaaS.
  • Digital Experience Monitoring: Reduce IT operational overhead and speed up ticket resolution with a unified view of application, cloud path, and endpoint performance metrics for analysis and troubleshooting.
  • Zero Trust Branch Connectivity: Reduce risk and complexity with non-routable branch and data center connectivity for users, servers, and IOT/OT devices.
  • DNS Security: Optimize DNS security and performance for all users, devices, and applications, on all ports and protocols, anywhere in the world
Zscaler Private Access (ZPA)
ZPA is the world’s most deployed ZTNA platform, applying the principle of least privilege to give users secure, direct connectivity to private applications running on-premises or in the public cloud while eliminating unauthorized access and lateral movement. As a cloud native service built on a holistic security service edge (SSE) framework, ZPA can be deployed in a matter of hours to replace legacy VPNs and remote access tools to:

  • Deliver a superior user experience: Connecting users directly to private apps eliminates slow, costly backhauling over legacy VPNs while continuously monitoring and proactively resolving user experience issues
  • Minimize the attack surface: Applications are made invisible to the internet preventing unauthorized users and devices from discovering them. The inside-out connections between user and app ensures apps and IPs are never exposed
  • Enforce least-privileged access: Application access is determined by identity and context— not an IP address—and users are never put on the network for access
  • Eliminate lateral movement: Applications are segmented so that users can only access a specific app, helping limit lateral movement
  • Stop cyberattacks with complete inspection: Private app traffic is inspected inline to prevent the most prevalent web attack techniques
  • Prevent data loss: Integrated DLP for private apps, advanced incident response and data classification to protect crown jewel apps
  • Detect compromised users and devices: Integrated decoys work to quickly identify and remove malicious users and devices
 
 
 
 

Cloud Security

Firewall Management

IPS (Intrusion Prevention System)

Load Balancer

Next Generation Firewall

SASE

SD-WAN

Security Service Edge (SSE)