Zero Trust là cách ra quyết định
Verify explicitly → least privilege → assume breach. Với web app, hãy xác minh identity/device, giới hạn network path, phân vùng workload, quan sát behavior và chuẩn bị response. Không có nút “Zero Trust” thay thế thiết kế.
Control map
- Defender for Cloud: posture/recommendations/workload signals tùy plan.
- NSG: network allow/deny ở subnet/NIC scope.
- Azure Firewall: centralized network traffic policy/inspection.
- WAF: application-layer HTTP protection.
- DDoS Protection: volumetric network attack protection/telemetry.
Bài tập
Threat-model web app và map control/evidence/owner/action. Viết runbook cho exposed port, suspicious sign-in và traffic flood. Với mỗi control ghi limitation và cost/exception.
Checkpoint
Bạn đạt bài khi biết một control bảo vệ layer nào và không hứa nó giải quyết threat ngoài scope.