- May 31, 2017
- 1,742
Hehehe, Andy, that is the EXACT verbiage that drives me absolutely insane .WDAC + ISG is smart deny-by-default in a similar meaning to CyberLock. It is not zero-trust, but it can be a part of Zero Trust Model in the meaning promoted by Microsoft:
Zero Trust Model - Modern Security Architecture | Microsoft Security
A Zero Trust model provides security against ransomware and cybersecurity threats by assigning the least required access needed to perform specific tasks.www.microsoft.com
WDAC + ISG is quite similar to CyberLock when it is OFF or on AutoPilot, and none of these configurations can possibly be part of a zero trust model, unless the model includes another blocking mechanism / layer that does not auto allow new, non-whitelisted items. ISG, WLC and VoodooAi are all highly effective, but they are not perfect.
ISG or WLC / VoodooAi are likely sufficient when the user is not engaging in risky activities, like browsing the web or checking email. But when the user is engaging in risky activities, auto allowing anything new is dangerous.