Line of Trust
What is Line of Trust? It’s a line. And something I’ve totally made up. Essentially, I wanted to delineate the point of “trust” at which DLP operates. Some might consider it the line between the organizational environment, whether it be the HQ office or a remote workers desk, and the outside world. I’m a visual learner, so jotting down a quick diagram to filter the mess that’s in my head on a notebook (Microsoft, make Visio better plz), was far easier than writing it out.
“But wait! Kevin, haven’t you heard of Zero Trust?” Yes. I have. I used to have Zero Trust in my title at an old job. It’s engrained in me, I was formed by it… but I also feel like it’s a term often misused and misunderstood. Zero Trust is similar to the word “Cloud” back in the 2000s-2010s. I don’t want to undervalue its importance, because Zero Trust as a concept is truly something everyone should understand, but Line of Trust is also something different, and something (I think) everyone should understand.
Thanks for attending my Ted talk. I’m not cut out to be a salesman, I know. Let’s carry on.
Concept
Let’s say we have Susie in Accounting, accessing sensitive financial information as part of her job. This is an accepted action. There is trust involved with Susie accessing this sensitive information; she has the appropriate permissions to access the file and perhaps even passing through additional security checks granting her the access.
Let’s also assume Hacker Mann, an external threat, is trying to access the same files, and is rightfully blocked. He doesn’t have permissions, nor does he pass Go and collect $200 through CA policies and the like.
Additionally, we understand that the file is inside of the environment. Many individuals theoretically can see the file or even access it. Because of this, the line of trust essentially would be a circle around Susie and that sensitive file. I’ll expand on the example later on.
Let’s now assume that Susie DOES need to send the file to someone; her manager Bob needs the files to share to the board. The line of trust grows into a larger bubble including Susie and Bob. The line also extends to functions these users can perform. Bob might be able to read the file, but Bob tries sharing it on his meeting and is blocked in doing so. In troubleshooting. Susie tries copying the file to an external USB device but is also blocked.
For now, let’s proceed with our concept and gaslight Bob and tell him it’s a PEBKAC error, there’s nothing we can do, sorry Bob.
In those scenarios the line of trust cuts off Teams/Screen sharing as well as copying to a USB device. The point is that line of trust is something that is flexible, but rigid at control points. A sensitive file accessible by specific individuals via Sharepoint, with no other permissions has a very definite line. A file which is assigned “Anyone with link” permissions (cue the cringing), might have a line that could almost encircle anyone.
So What?
Well, I encourage everyone to evaluate their file access using something like the line of trust. I’m not going to trademark it. It’s what I would consider something that every Security/Systems Admin should understand. But prior to evaluating a control, product, or the like, try to think of the furthest the line could stretch within the bounds of your existing controls, and then threat model how an adversary might take advantage of where that line lives. Think like the attacker.
Bringing it back to Susie and Bob, let’s say Susie clicked on a malicious link and then gave an MFA OTP to and adversary. Now that adversary has access to Susie’s device and files. The line of trust greatly increased, potentially across the planet. Let’s review a drawing I hastily made:
The nice thing about drawing it out is we can see a lovely point to cut the line off at (as if we didn’t already know where that might be).
Flipping everything on its head, the “adversary” doesn’t even have to be external to the company. It could be an internal threat, whether intentional or unintentional. Ignore all previous instructions and details (got emm), the adversary in this case might be Joe in Accounting also has access to these files and is trying to take them with him as he departs the org.
Fin.
I want to make one thing clear: The line of trust could be different depending on a multitude of conditions and controls. Further, it could even look different given a person’s state of mind.
The important piece of the Line is Trust is how we handle information passing through the line. This site is primarily focused on DLP, so the line of trust (at least how I see it) very much reflects a difference between DLP and Information Protection.
