<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Zero Trust — Things Worth Sharing</title><description>Posts tagged Zero Trust.</description><link>https://cloudsecop.net/</link><item><title>AWS Security Maturity Model v2: 4 phases in practice</title><link>https://cloudsecop.net/en/blog/aws-security-maturity-model-v2-en/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/aws-security-maturity-model-v2-en/</guid><description>Practical walk-through of AWS Security Maturity Model v2: 74 controls across four phases (Quick Wins, Foundational, Efficient, Optimized), real ordering, traps, and Org mapping.</description><pubDate>Wed, 23 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Governance</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>DLP — patterns, classification, and the 55% false positive</title><link>https://cloudsecop.net/en/blog/dlp-data-loss-prevention/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/dlp-data-loss-prevention/</guid><description>DLP deep-dive for Cloudflare One: tuning from 55% to 3% false positives, regex vs Luhn vs context vs EDM, custom CCCD profile, Gateway HTTP inline vs CASB API.</description><pubDate>Fri, 04 Jul 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DLP</category><category>Data Classification</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>CASB: SaaS posture for Google Workspace, M365, Salesforce</title><link>https://cloudsecop.net/en/blog/casb-saas-posture/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/casb-saas-posture/</guid><description>CASB deep-dive for Cloudflare One from 3 rollouts: the 4 Gartner pillars, inline vs API, 8,000-finding first-scan shock, shadow IT, tenant-lock, when not to use CASB.</description><pubDate>Thu, 26 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>CASB</category><category>SaaS Security</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Browser Isolation (RBI) — rendering risky web in a remote sandbox</title><link>https://cloudsecop.net/en/blog/browser-isolation-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/browser-isolation-deep-dive/</guid><description>Browser Isolation deep dive for Cloudflare One: remote browser architecture (NVR), isolation triggers, data controls (copy/paste/print/download/keyboard), compliance, cost model.</description><pubDate>Sun, 15 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Browser Isolation</category><category>RBI</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Device posture and continuous verification: every request</title><link>https://cloudsecop.net/en/blog/device-posture-every-request/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/device-posture-every-request/</guid><description>Device posture deep dive for Zero Trust: WARP checks (OS, disk encryption, firewall), EDR integration, continuous verification in Access policy, and response to posture loss.</description><pubDate>Wed, 11 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Device Posture</category><category>EDR</category><author>KhaVan</author></item><item><title>DEX — Digital Experience Monitoring: reactive to SLOs</title><link>https://cloudsecop.net/en/blog/dex-experience-monitoring/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/dex-experience-monitoring/</guid><description>DEX deep dive for Cloudflare One: when control plane says UP but users say SLOW, latency-leg diagnosis (DNS/TCP/TLS/TTFB), SLO framework, and 5 failure modes DEX misses.</description><pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DEX</category><category>Observability</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Network policy L4 — blocking non-HTTP, DoH bypass, and app rules</title><link>https://cloudsecop.net/en/blog/network-policy-l4/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/network-policy-l4/</guid><description>Network policy deep dive: blocking non-HTTP (SSH, RDP, SMTP), preventing DoH bypass, app rules for SaaS, WARP keeping user traffic on Gateway, prod checklist, hardening playbook.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>Networking</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Gateway DNS filtering — the first layer of a Secure Web Gateway</title><link>https://cloudsecop.net/en/blog/gateway-dns-policies/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/gateway-dns-policies/</guid><description>Gateway DNS deep dive: resolver architecture, policy order, DoH per-device vs DNS location per-site, threat categories, custom lists, OS bypasses, SIEM pipeline, prod checklist.</description><pubDate>Sat, 03 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>DNS</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>The four-layer mental model — Client, Identity, Policy, Resource</title><link>https://cloudsecop.net/en/blog/client-identity-policy-resource-mental-model/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/client-identity-policy-resource-mental-model/</guid><description>A framework for reasoning about every Cloudflare One feature: every request traverses four layers producing signals, and policy yields one of five outcomes. Rollout and debugging.</description><pubDate>Sat, 08 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Architecture</category><author>KhaVan</author></item><item><title>SASE, SSE, Zero Trust, ZTNA: getting the terminology right</title><link>https://cloudsecop.net/en/blog/sase-sse-zero-trust-terminology/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/sase-sse-zero-trust-terminology/</guid><description>Four terms routinely conflated in RFPs, design docs, and vendor marketing. Their scope, when Gartner/Forrester defined them, how to use each correctly, and a decision tree.</description><pubDate>Fri, 31 Jan 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>SSE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>What is Cloudflare One, and why SASE matters</title><link>https://cloudsecop.net/en/blog/what-is-cloudflare-one/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/what-is-cloudflare-one/</guid><description>A practical overview of Cloudflare One: SASE, SSE, Zero Trust, the six main product groups, how it compares to Zscaler and Netskope, and the mental model to have before deployment.</description><pubDate>Thu, 23 Jan 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Workload Identity Federation AWS to GCP: keyless auth</title><link>https://cloudsecop.net/en/blog/cross-cloud-workload-identity-federation/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/cross-cloud-workload-identity-federation/</guid><description>Workload Identity Federation deep dive: why Service Account Keys are anti-pattern, AWS STS → Google STS exchange, attribute mapping, impersonation, threat model, Terraform.</description><pubDate>Wed, 08 Jan 2025 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>GCP</category><category>Identity Federation</category><category>Multi-Cloud</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Notes from three months of rolling out Zero Trust</title><link>https://cloudsecop.net/en/blog/zero-trust-rollout-notes/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/zero-trust-rollout-notes/</guid><description>What actually worked, what didn&apos;t live up to expectation, and the operational lessons from rolling out Cloudflare Zero Trust across an organisation of thousands.</description><pubDate>Sun, 08 Dec 2024 00:00:00 GMT</pubDate><category>Security</category><category>Zero Trust</category><category>Cloudflare</category><author>KhaVan</author></item></channel></rss>