| name | implementing-zero-trust-in-cloud |
| description | Use when this skill guides organizations through implementing zero trust architecture in cloud environments following NIST SP 800-207 and Google BeyondCorp principles. It covers identity-centric access controls, micro-segmentation, continuous verification, device trust assessment, and deploying Identity-Aware Proxy to eliminate implicit network trust in AWS, Azure, and GCP environments. |
| domain | cybersecurity |
| tags | ["zero-trust","beyondcorp","identity-aware-proxy","micro-segmentation","continuous-verification"] |
| subdomain | cloud-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"] |
Implementing Zero Trust In Cloud
Overview
Cybersecurity skill for implementing zero trust in cloud. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"implementing zero trust in cloud"
-
"This skill guides organizations through implementing zero trust architecture in "
-
When migrating from traditional perimeter-based security to identity-centric access controls
-
When eliminating VPN dependencies for remote workforce access to cloud applications
-
When implementing continuous verification for every access request regardless of network location
-
When designing micro-segmentation strategies for multi-cloud workloads
-
When regulatory requirements mandate zero trust architecture adoption (federal mandates, NIST guidelines)
Do not use for simple VPN replacement without broader architectural changes, for network firewall rule management alone (see implementing-cloud-network-segmentation), or for identity provider initial setup (see managing-cloud-identity-with-okta).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Identity provider capable of OIDC/SAML integration (Okta, Azure AD, Google Workspace)
- Device management solution for endpoint trust assessment (Intune, Jamf, Google Endpoint Verification)
- Cloud workloads accessible via HTTPS with load balancer or reverse proxy infrastructure
- SIEM platform for continuous monitoring of access decisions and anomaly detection
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: ) -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}