<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Zero Trust — Things Worth Sharing</title><description>Bài viết gắn tag Zero Trust.</description><link>https://cloudsecop.net/</link><item><title>AWS Security Maturity Model v2: 4 phase áp dụng thực tế</title><link>https://cloudsecop.net/blog/aws-security-maturity-model-v2/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-maturity-model-v2/</guid><description>AWS Security Maturity Model v2: 74 kiểm soát chia 4 giai đoạn (Quick Wins, Foundational, Efficient, Optimized), thứ tự nên làm, bẫy thường gặp, ánh xạ vào Organization.</description><pubDate>Sun, 27 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Governance</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>DLP: pattern, classification và 55% false positive</title><link>https://cloudsecop.net/blog/dlp-data-loss-prevention-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/dlp-data-loss-prevention-deep-dive/</guid><description>DLP đào sâu cho Cloudflare One: tinh chỉnh từ 55% FP về 3%, regex vs Luhn vs context vs EDM, profile CCCD Việt Nam, Gateway HTTP inline vs CASB API.</description><pubDate>Mon, 30 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DLP</category><category>Data Classification</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>CASB: posture và misconfig SaaS (GWorkspace, M365, SF)</title><link>https://cloudsecop.net/blog/casb-saas-posture-misconfig/</link><guid isPermaLink="true">https://cloudsecop.net/blog/casb-saas-posture-misconfig/</guid><description>CASB deep-dive cho Cloudflare One từ 3 lần triển khai: 4 trụ cột Gartner, inline vs API, phản ứng 8000 finding tuần đầu, shadow IT discovery, tenant lock, khi nào KHÔNG dùng CASB.</description><pubDate>Mon, 23 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>CASB</category><category>SaaS Security</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Browser Isolation (RBI): render risky web trong sandbox remote</title><link>https://cloudsecop.net/blog/browser-isolation-rbi-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/browser-isolation-rbi-deep-dive/</guid><description>Browser Isolation deep-dive cho Cloudflare One: kiến trúc remote browser (NVR), kích hoạt isolation, kiểm soát dữ liệu (copy/paste/print/download/keyboard), compliance, chi phí.</description><pubDate>Thu, 19 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Browser Isolation</category><category>RBI</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Device posture và continuous verification mọi request</title><link>https://cloudsecop.net/blog/device-posture-continuous-verification/</link><guid isPermaLink="true">https://cloudsecop.net/blog/device-posture-continuous-verification/</guid><description>Device posture đào sâu cho Zero Trust: WARP check (OS, mã hóa ổ đĩa, firewall), EDR (CrowdStrike, SentinelOne, Defender), continuous verification trong Access policy, truy nguyên.</description><pubDate>Sat, 07 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Device Posture</category><category>EDR</category><author>KhaVan</author></item><item><title>DEX: Digital Experience Monitoring và proactive SLO</title><link>https://cloudsecop.net/blog/dex-digital-experience-monitoring/</link><guid isPermaLink="true">https://cloudsecop.net/blog/dex-digital-experience-monitoring/</guid><description>DEX đào sâu cho Cloudflare One: khi control plane UP mà người dùng thấy chậm, chẩn đoán từng chặng (DNS/TCP/TLS/TTFB), SLO framework, 5 chế độ hỏng DEX không thấy.</description><pubDate>Fri, 30 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DEX</category><category>Observability</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Cloudflare Access vs AWS IAM Identity Center cho team admin</title><link>https://cloudsecop.net/blog/cloudflare-access-vs-aws-iam-idc/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-access-vs-aws-iam-idc/</guid><description>Đừng cố unify Cloudflare Access và AWS IAM Identity Center. Pattern thực dụng: Okta/Entra → SSO cả hai, SCIM provisioning, per-app policy, audit correlation.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>AWS</category><category>Identity</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Network policy L4: chặn non-HTTP, DoH bypass và app rule</title><link>https://cloudsecop.net/blog/network-policy-l4-non-http/</link><guid isPermaLink="true">https://cloudsecop.net/blog/network-policy-l4-non-http/</guid><description>Network policy deep-dive: chặn non-HTTP (SSH, RDP, SMTP), chặn DoH bypass DNS filter, app rule cho SaaS, kết hợp WARP, checklist production và playbook siết chặt.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>Networking</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Gateway DNS filtering: lớp đầu tiên của Secure Web Gateway</title><link>https://cloudsecop.net/blog/gateway-dns-filtering/</link><guid isPermaLink="true">https://cloudsecop.net/blog/gateway-dns-filtering/</guid><description>Gateway DNS deep-dive: kiến trúc resolver, thứ tự policy, DoH per-device vs DNS location per-site, threat intel category, custom list, log SIEM, checklist production.</description><pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>DNS</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Mental model 4 tầng: Client, Identity, Policy, Resource</title><link>https://cloudsecop.net/blog/mental-model-client-identity-policy-resource/</link><guid isPermaLink="true">https://cloudsecop.net/blog/mental-model-client-identity-policy-resource/</guid><description>Khung tư duy cho mọi tính năng Cloudflare One: mỗi request đi qua 4 tầng sinh tín hiệu, policy đánh giá rồi đi tới 1 trong 5 kết quả. Triển khai và truy nguyên dễ hơn nhiều.</description><pubDate>Sat, 15 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Architecture</category><author>KhaVan</author></item><item><title>SASE, SSE, Zero Trust, ZTNA: phân biệt thuật ngữ trước khi sa lầy</title><link>https://cloudsecop.net/blog/sase-sse-zero-trust-thuat-ngu/</link><guid isPermaLink="true">https://cloudsecop.net/blog/sase-sse-zero-trust-thuat-ngu/</guid><description>Ba thuật ngữ dễ dùng lẫn lộn trong RFP, design doc và tiếp thị. Phân biệt phạm vi, thời điểm xuất hiện, cách dùng đúng, và decision tree nhỏ để chọn đúng từ trong từng ngữ cảnh.</description><pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>SSE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Workload Identity Federation AWS sang GCP: keyless auth</title><link>https://cloudsecop.net/blog/workload-identity-federation-aws-gcp/</link><guid isPermaLink="true">https://cloudsecop.net/blog/workload-identity-federation-aws-gcp/</guid><description>Workload Identity Federation deep dive: vì sao Service Account Key là anti-pattern, luồng token AWS STS → Google STS, attribute mapping, impersonation, threat model, Terraform.</description><pubDate>Mon, 27 Jan 2025 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>GCP</category><category>Identity Federation</category><category>Multi-Cloud</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Cloudflare One là gì, và vì sao SASE quan trọng</title><link>https://cloudsecop.net/blog/cloudflare-one-la-gi/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-one-la-gi/</guid><description>Một tổng quan thực dụng về Cloudflare One: SASE, SSE, Zero Trust, 6 nhóm sản phẩm chính, cách so sánh với Zscaler/Netskope, và mô hình tư duy cần có trước khi triển khai.</description><pubDate>Sat, 04 Jan 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Ghi chép sau 3 tháng triển khai Zero Trust</title><link>https://cloudsecop.net/blog/zero-trust-notes/</link><guid isPermaLink="true">https://cloudsecop.net/blog/zero-trust-notes/</guid><description>Những điều thực sự hiệu quả, những thứ không như kỳ vọng, và các bài học vận hành khi triển khai Cloudflare Zero Trust cho tổ chức quy mô hàng ngàn người dùng.</description><pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate><category>Security</category><category>Zero Trust</category><category>Cloudflare</category><author>KhaVan</author></item></channel></rss>