# Note # 1: Zero Trust Strategy

## **Cybersecurity Architect Roles and Tools:**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1737662370641/c6f087ad-2292-443d-9cc3-8f072365522d.png?auto=compress,format&format=webp&q=75 align="center")

### **Cybersecurity Hierarchy**

1. **Business Leadership:**
    
    * CEO: Focuses on business goals and digital transformation.
        
2. **Technical Leadership:**
    
    * CIO (Chief Information Officer) and CISO (Chief Information Security Officer): Develop security strategy and integrate business with security.
        
        * They analyze strategies but do not implement them.
            
3. **Architects and Technical Managers\***: Responsible for designing architecture, creating policies, and planning (implementation is not included yet).
    
    <mark>See the details below in the next paragraph.</mark>
    
4. **Security Engineers and Operations:**
    
    Handle implementation, monitoring, response, and investigations.
    

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1737658307123/aa65c80a-2a5b-4e12-9505-d984c017b326.webp?auto=compress,format&format=webp&q=75 align="center")

### **<mark>*Cybersecurity Architect:</mark>**

A Cybersecurity Architect focuses on prevention by managing GRC (Governance, Risk, and Compliance) and understanding and improving the security posture. In terms of protection, they ensure security for identity, devices, data, and applications. When it comes to investigating and responding to incidents, they are involved in security operations, managing the SOC (Security Operations Center), and handling incidents, So:

***Prevent:***

* *GRC (Governance, Risk, and Compliance)*
    
* *Security Posture: Understand and improve the security posture.*
    

***Protect:***

* *Ensure security for identity, devices, data, and applications.*
    

***Investigate/Respond to Incidents:***

* *Security Operations*
    
* *Manage SOC (Security Operations Center).*
    
* *Handle incidents.*
    

### ***Tools for Cybersecurity Architects: Tools we can use to define framework, architecture, etc.***

1. **CAF (Cloud Adoption Framework):** Start with CAF. It provides different steps to help us deploy infrastructure or migrate to the cloud. It helps identify strategies, objectives, and motivations. In these steps, we need to study security, manage resources, and governance.
    

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1737662675134/6108b10c-0645-4590-aa0e-36bc7cbf39c6.png?auto=compress,format&format=webp&q=75 align="center")

2. **MCRA (Microsoft Cybersecurity Reference Architecture):** This shows how to integrate solutions. We can use it as a reference when building architecture if we don't know where to start. [**Download the December 2023 version of the MCRA**](https://github.com/MicrosoftDocs/security/blob/main/Downloads/mcra-december-2023.pptx?raw=true).
    

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1737663290650/35750159-acb3-4ba6-b325-f393501c7ffa.png?auto=compress,format&format=webp&q=75 align="center")

**3\. WAF (Well-Architected Framework):** Guidance on:

* Reliability
    
* Cost optimization
    
* Operational excellence
    
* Performance efficiency
    
* Security
    

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1737665425340/fd72bbd5-01e8-4aa8-969c-e732cac6ca18.png?auto=compress,format&format=webp&q=75 align="center")

4. **Zero Trust Model (Global Framework):** These tools help us define all our security strategies. This involves not only cybersecurity architecture but also technical leadership, as it includes all security strategies. All designs must follow the principles of zero trust.
    

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1737665544423/abcb4a23-f970-440e-a480-2dae2fdd91eb.jpeg?auto=compress,format&format=webp&q=75 align="center")
