Zero trust policy manager
In some aspects, a method for managing security policies on a network may include a policy manager receiving, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services. The policy manager may also compare the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status. Finally, the policy manager may present a visual representation of the security data that includes at least an indication of the one or more discrepancies.
1 . A computer-implemented method for managing security policies on a network, comprising:
receiving, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services;
comparing the information descriptive of the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status by identifying portions of the information descriptive of the security policy data that are not reflected in the security status of at least one network connection; and
presenting an interactive visual representation, the interactive visual representation includes the security data that includes at least an indication of the one or more discrepancies, an overall threat level, and at least a portion of the network.
2 . The computer-implemented method of claim 1 , further comprising:
receiving a request to update the security policy data, wherein the request includes a modification to the security policy data associated with the one or more security services; and
transmitting the request to a policy modification program, wherein when received by the policy modification program, the policy modification program distributes the modification to the security policy data to at least one of the one or more security services.
3 . The computer-implemented method of claim 2 , wherein the at least one of the one or more security services implements the modification to the security policy data on the network.
4 . The computer-implemented method of claim 1 , further comprising: generating a database comprised of at least the one or more security services and the security data.
5 . The computer-implemented method of claim 4 , wherein the database has a hierarchical tree structure comprised of objects and arrays, and wherein the hierarchical tree structure includes at least a user, user group, a device, and a network access method based on the security data.
6 . The computer-implemented method of claim 1 , wherein the visual representation is configured as a matrix, indicating at least a device and one or more network connections associated with the device.
7 . The computer-implemented method of claim 1 , wherein the visual representation is configured to display security data according to workforce, workplace, or workload.
8 . The computer-implemented method of claim 1 , further comprising:
updating the visual representation according to periodic updates to the security data as indicated by a security policy associated with the network.
9 . A system comprising:
one or more processors; and
a memory storing instructions that, when executed by the one or more processors, configure the system to:
receive, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services;
compare the information descriptive of the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status by identifying portions of the information descriptive of the security policy data that are not reflected in the security status of at least one network connection; and
present an interactive visual representation, the interactive visual representation includes the security data that includes at least an indication of the one or more discrepancies, an overall threat level, and at least a portion of the network.
10 . The system of claim 9 , wherein the instructions further configure the system to:
receive a request to update the security policy data, wherein the request includes a modification to the security policy data associated with the one or more security services; and
transmit the request to a policy modification program, wherein when received by the policy modification program, the policy modification program distributes the modification to the security policy data to at least one of the one or more security services.
11 . The system of claim 10 , wherein the at least one of the one or more security services implements the modification to the security policy data on the network.
12 . The system of claim 9 , wherein the instructions further configure the system to:
generate a database comprised of at least the one or more security services and the security data.
13 . The system of claim 12 , wherein the database has a hierarchical tree structure comprised of objects and arrays, and wherein the hierarchical tree structure includes at least a user, user group, a device, and a network access method based on the security data.
14 . The system of claim 9 , wherein the visual representation is configured as a matrix, indicate at least a device and one or more network connections associated with the device.
15 . The system of claim 9 , wherein the visual representation is configured to display security data according to workforce, workplace, or workload.
16 . The system of claim 9 , wherein the instructions further configure the system to:
update the visual representation according to periodic updates to the security data as indicated by a security policy associated with the network.
17 . A non-transitory computer-readable storage medium, the non-transitory computer-readable storage medium including instructions that when executed by a computer, cause the computer to:
receive, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services;
compare the information descriptive of the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status by identifying portions of the information descriptive of the security policy data that are not reflected in the security status of at least one network connection; and
present an interactive visual representation, the interactive visual representation includes a the security data that includes at least an indication of the one or more discrepancies, an overall threat level, and at least a portion of the network.
18 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions further configure the computer to:
receive a request to update the security policy data, wherein the request includes a modification to the security policy data associated with the one or more security services; and
transmit the request to a policy modification program, wherein when received by the policy modification program, the policy modification program distributes the modification to the security policy data to at least one of the one or more security services.
19 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions further configure the computer to:
generate a database comprised of at least the one or more security services and the security data.
20 . The non-transitory computer-readable storage medium of claim 19 , wherein the database has a hierarchical tree structure comprised of objects and arrays, and wherein the hierarchical tree structure includes at least a user, user group, a device, and a network access method based on the security data.