Home / Companies / Evervault / Blog / Post Details
Content Deep Dive

A security paradigm for 2024: ATAF—Access To, Access From

Blog post from Evervault

Post Details
Company
Date Published
Author
Mathew Pregasen
Word Count
1,234
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

Security teams in 2023 face the challenge of selecting effective strategies from a multitude of security techniques to protect systems and data from breaches. The ATAF (Access To, Access From) framework is recommended as a comprehensive approach to security, which involves categorizing tactics into pre-attack and post-attack protection. ATAF defines "Access To" as access to valuable resources, while "Access From" refers to the access those resources have to other resources, emphasizing containment if an exploit occurs. This approach acknowledges that while airtight security is unrealistic, minimizing damage is crucial. Four strategies under ATAF include the principle of least privilege, just-in-time access, secrets managers, and encryption by relay, each designed to limit the impact of a breach by restricting access and protecting sensitive data. ATAF can be applied beyond credential-based access to network resources and external applications, encouraging a holistic view of security that prioritizes making breaches more difficult and less damaging.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.