APAC CIOOutlook
About UsConferencePartner With Us
  • Technologies
    • Blockchain
      Data Intelligence and Management
      Digital Transformation
      FinTech
      Generative and Agentic AI
      Low Code No Code
      Mobile Application
      Networking
      Robotics
      Storage
      Wireless
  • Industries
    • Automotive
      Aviation
      Banking
      Construction
      E-Commerce
      Food and Beverages
      Healthcare
      Insurance
      Logistics
      Manufacturing
      Retail
      Supply Chain
      Travel and Hospitality
  • Platforms
    • Microsoft
      Salesforce
      SAP
  • Strategic Solutions
    • Business Intelligence
      Contact Center
      Corporate Finance
      CRM
      Cyber Security
      Data Center
      Enterprise Asset Management
      Enterprise Performance Management
      IT Infrastructure and Services
      Managed Services
      Procurement
      Unified Communication
      Workflow
  • Home
  • CXO Insights
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Whitepapers
  • CXO Awards
#

Apac CIOOutlook Weekly Brief

×

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

Subscribe

loading

THANK YOU FOR SUBSCRIBING

  • Home
  • Cyber Security
Editor's Pick (1 - 4 of 8)
left
Cyber Security - Integrated enterprise approach required to address the multifaceted challenges

Sumit Puri, CIO, Max Healthcare

Driving Business Agility

Cindy McKenzie, CIO, Deluxe Entertainment Services Group, Inc.

The Road Towards the Intelligent Enterprise

Florian Roth, CIO and Head, IT Services, SAP SE(FWB: SAP)

Culture Eats Strategy For Breakfast, Lunch, And Dinner

Julie Valencia, Head of Customer Care, Paymark

Digital Transformation - The Right Way

Amit Goel, CIO, Metropolis Healthcare

Innovation Isn't Easy

Rowan Dollar, CIO, Information and Technology, Department Of Primary Industry and Services, Northern Territory Government

IT Service Management in the Digital Era

Unal Altay, CIO, V/line

Service Driven Technology

Les Ottolenghi, EVP & CIO, Caesars Entertainment

right

Where Am I With Zero Trust? The CISO's Reality

Charmaine Valmonte, Fvp & Chief Information Security Officer | Data Protection Officer, Aboitiz Group

Tweet
content-image

Charmaine Valmonte, Fvp & Chief Information Security Officer | Data Protection Officer, Aboitiz Group

Cybersecurity has been a top priority for most organizations for the past decade. A large portion of an organization’s operational budget is spent on state-ofthe-art technologies as a means to protect the business from the threats of a cyber attack. However, technology is not the definitive solution to eliminate or reduce the risk; a disruption causing major losses can happen if the process and people are excluded from the equation.

The transformed cybersecurity professional expects a cyber attack to happen anytime and come from anywhere. Today’s CISO must accept that the organization will continue to transform. The perimeters we’ve since built for the organization cannot contain or protect today’s evolving environment.

Zero Trust, defined by the National Institute of Standards and Technology in its Special Publication 800-207, states that “Zero Trust presents a shift from a location-centric model to a data-centric approach for fine-grained security controls between users, systems, data and assets that change over time”. What does this mean to a CISO who has spent the last decade creating perimeters to protect the organization? Where do we start? The answer will depend on where we are in the Zero Trust maturity Model against the CISO’s Cybersecurity Roadmap. A careful review of what you have in place against this model is a good starting point.

Implementing Zero Trust involves a careful inventory of your organization’s identities, devices, environment, applications, and data. Zero Trust is not simply about implementing technological solutions to protect the organization. A clear understanding of the business and its transformation strategies is likewise important. This is especially true for hybrid organizations that will continually transition toward a cloud or service-enabled environment.

The Cybersecurity and Infrastructure Security Agency, Cyber Division in its Pre-decisional Draft of the Zero Trust Maturity Model, Version 1.0, June 2021, presented a high-level view of the Zero Trust Maturity Model across each maturity stage.

An organization’s security controls can be mapped into this recommended model regardless of its architecture. We must understand where our organization truly stands in each of the pillars as prescribed. The maturity levels are summarized as follows.

Traditional - manually configured systems and policies, siloed point solutions that require a manual incident response, mitigation, and deployment.

Advanced - semi-automated, cross-pillar coordination, centralized identities, controls, visibility, and automation with the capability to deploy predefined mitigations and controls.

Implementing Zero Trust Involves A Careful Inventory Of Your Organization’s Identities, Devices, Environment, Applications, And Data

Optimal - fully automated with dynamic least-privilege access, interoperable across pillars with centralized and orchestrated visibility.

As the business continues to transform, the CISO must understand the who and what identities access what data and where.

Is multi-factor authentication a standard across the workforce to include its 3rd party providers? Does the CISO have a clear inventory of the organization’s data across all environments? Is there a clear inventory of all systems and workloads across the enterprise? As we journey through this model, we may realize that the security program can be at different levels in each of these pillars. Understanding where we are in this maturity model allows us to build the requisite controls to support and protect the organization and its business objectives.

tag

inventory

cyber attack

review

Weekly Brief

loading
Top 10 Cyber Security Companies in APAC - 2024
Featured Issue

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

APAC CIOOutlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@apacciooutlook.com
  • sales@apacciooutlook.com
  • marketing@apacciooutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 APAC CIOOutlook. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://cyber-security.apacciooutlook.com/cxoinsights/where-am-i-with-zero-trust-the-cisos-reality-nwid-10223.html