Organizations don't have an identity crisis. They have a trust accounting crisis. Nobody is keeping the books.
Security has gone through two eras of defining itself by what it measures. In the 1990s, security meant the firewall: define the perimeter, control what crosses it. In the 2010s, as the perimeter dissolved into cloud and SaaS, security redefined itself around identity: Who are you, and what have we verified about you? Both eras produced real, durable progress. Both also quietly assumed the same thing — that once something was verified, it could be trusted going forward without much further scrutiny. That assumption held up reasonably well when the things being verified were mostly people.
This article has been indexed from DZone Security Zone
Read the original article: