With the increase of distributed IT environments, security teams face more access requests, more devices, more applications, and more policy changes. The traditional approach usually involves manual analysis by the administrators who then decide whether the changes fall into the existing security policies.
AI technology begins to reshape how some of these administrative tasks are done. It can be used as an assistant for analyzing the data, preparing for the policy changes, and assisting in understanding complex environments instead of replacing security administrators.
From Manual Security Policies to AI-Assisted Decision Making
It becomes challenging to manage access when organizations have hundreds of users and devices. The request of providing access to the developer for the internal service looks like a simple task but involves identity checks, device checks, permission checks, the network, and many other factors.
The AI-assisted systems will allow security teams to interpret all these factors and generate the security policies out of them. Instead of making changes to the environment right away, the system will provide the suggested action for approval.
According to AI Operator documentation from QuickZTNA, it is possible to use AI to generate and preview administrative changes.
This workflow model helps to ensure that, while automation does not exclude unrestricted access, human approval can always be involved.
Visibility is as Important as Access Control
One other problem that arises in this scenario is understanding what takes place once access has been provided.
The security team may be required to investigate any suspicious activity, assess software use, check the session history, or determine which of the devices could be considered as a potential threat. Such data collection may serve as additional context when deciding on the relevance of the existing policy.
One of such examples is workforce analytics. While conventional monitoring includes only the login events, the alternative method allows for a more extensive analysis.
There is detailed description of the capabilities in the Workforce Analytics documentation. They include session activity, software inventory, DNS categories, patch information, and user risk scores.
The Privacy Issue
The more information collected, the more questions about the extent of the collection arise.
It is crucial to determine a goal for the monitoring. Otherwise, any unnecessary collection may bring privacy, compliance, and trust issues.
A better strategy is to gather information which actually helps with security or operation purposes, and then develop proper retention and access policies. Communication of what is monitored and why also needs to be performed.
This becomes especially relevant when it comes to distributed staff working on multiple networks with different devices.
Where Does AI Fit into Zero Trust?
AI cannot affect the fundamentals of Zero Trust architecture, including identity verification, least privilege access, securing of devices, segmentation, and continuous assessment of security.
At the same time, AI can become one more layer surrounding these operations since it helps administrators to understand the gathered information and prepare changes faster.
The general point here is not to automate all the decisions related to cybersecurity but to decrease administrative load while ensuring transparency of decisions made.
As companies start experimenting with AI assistance in security management, the most effective solutions can turn out to be those which combine both automation and visibility.
Responses
Join the conversation
Sign in to share your thoughts and interact with the author.
Sign In to Comment