Zero Trust Maturity Cross-Cutting Capabilities

Introduction

This section covers the cross-cutting capabilities needed for the Zero Trust Maturity Foundation. It illustrates how existing TRA Business Rules and Recommended Practices align with these capabilities.

CMS Guidance

Each pillar also implements three cross-cutting capabilities. Visibility and Analytics refers to how we monitor systems. Automation and Orchestration is the process of creating reusable processes that can be automated within our systems. And Governance is the policies we set for the systems as well as how we track how we enforce those policies.

The CMS Zero Trust Workgroup is developing guidelines for CMS ADOs. Specific guidance can be found in CMS Cloud documentation: Zero Trust Maturity for AWS for CMS Cloud. This includes:

  • Using existing logging, monitoring, and alerting infrastructure where possible
  • Centralizing the implementation of the cross-cutting capabilities over all five of the other pillars
  • Documenting policies and procedures so they can be automated

Capabilities

The business rules shown beneath each capability aren’t comprehensive — Other requirements are defined in the ARS and RMH.

Zero Trust Visibility and Analytics Capabilities
Traditional Initial Advanced Optimal
Agency manually collects limited logs across their enterprise with low fidelity and minimal analysis. Agency begins to automate the collection and analysis of logs and events for mission critical functions and regularly assesses processes for gaps in visibility. Agency expands the automated collection of logs and events enterprise-wide (including virtual environments) for centralized analysis that correlates across multiple sources. Agency maintains comprehensive visibility enterprise-wide via centralized dynamic monitoring and advanced analysis of logs and events.
Zero Trust Automation and Orchestration Capabilities
Traditional Initial Advanced Optimal
Agency relies on static and manual processes to orchestrate operations and response activities with limited automation. Agency begins automating orchestration and response activities in support of critical mission functions. Agency automates orchestration and response activities enterprise-wide, leveraging contextual information from multiple sources to inform decisions. Agency orchestration and response activities dynamically respond to enterprise-wide changing requirements and environmental changes.
Zero Trust Governance Capabilities
Traditional Initial Advanced Optimal
Agency implements policies in an ad hoc manner across the enterprise, with policies enforced via manual processes or static technical mechanisms. Agency defines and begins implementing policies for enterprise-wide enforcement with minimal automation and manual updates. Agency implements tiered, tailored policies enterprise-wide and leverages automation where possible to support enforcement. Access policy decisions incorporate contextual information from multiple sources. Agency implements and fully automates enterprise-wide policies that enable tailored local controls with continuous enforcement and dynamic updates.