Available on Demand | May 29, 2025 | 2 Hours | 2 CPE
State and local, territorial, and tribal governments are not bound by the federal agency mandate to implement zero trust architectures, but there are numerous reasons they are either considering it or taking action to put it in place.
Zero trust is a particularly important concept for these smaller government bodies because they own and operate critical infrastructure and provide vital day-to-day services to their residents, from issuing driver’s licenses to approving building permits. It also helps these governments comply with various privacy and security regulations, such as the Health Insurance Portability and Accountability Act (HIPAA), which protects sensitive health information from being disclosed without the patient’s consent.
Join us as thought leaders from state and local agencies and the cybersecurity industry discuss the nuances of implementing going even further than ZT, to least permissive, the challenges they have addressed and the benefits they have seen, and ways to build on it to strengthen cyber protections even more.
Day One: Beyond Zero Trust – Building Federal Cyber Resilience
We’ll Discuss:
Accreditation:
Participants can earn 2 CPE credits in Business Management & Organization.*
* To receive CPE credit you must arrive on time and participate in the surveys throughout the webinar. Certificates will be e-mailed to registrants. In accordance with the standards of the National Registry of CPE Sponsors, 50 minutes equals 1 CPE. By providing your contact information to us, you agree: (i) to receive promotional and/or news alerts via email from Federal News Network and our third party partners, (ii) that we may share your information with our third party partners who provide products and services that may be of interest to you and (iii) that you are not located within the European Economic Area.
What is CART?
CART (communication access realtime translation) provides instant accessibility for all participants by delivering the spoken word as a realtime stream of text.
CART Captioner Professional Certifications
Our CART services are provided by Home Team Captions. All of our CART captioners hold, at minimum, the CCP (Certified CART Provider) certification, or higher, from NCRA (National Court Reporters Association.)
To view the CART feed for this webinar: Register for this webinar, login from the link provided, and click on the CART Tab and click the link to begin using CART.
Hosted By:
Open Remarks:
Session One: Beyond Zero Trust — Embracing Least Permissive Trust
The premise of zero trust architectures is based on the maxim “never trust, always verify.” This can be difficult when working with siloed legacy systems, where communication links are tenuous because of proprietary technology or don’t exist because they were never connected to each other. Additionally, ZT is identity-based, but users often have multiple “identities” depending on their physical location, their day-to-day work, groups they may belong to, etc. Incorporating the concept of “least permissive trust” takes identity-based access one step further.
Session Two: The Building Blocks of Least Permissive Trust: ICAM & Micro-Segmentation
Micro-segmentation – dividing networks into smaller segments that can be isolated, often at the individual workload level – mitigates threats from users that legitimately have access to one part of a system but should not be able to move laterally to other parts of that system. Identity Credential Access Management (ICAM), compliments micro-segmentation, ensuring that access and permission is specifically in line with the persona attached to them. Both network solutions embody the tenants of Least Permissive Trust, building flexible, responsive controls that can block unexpected or inappropriate movements within a network.
Session Three: Applying Analytics to Least Permissive
Maximizing the value of identity verification and network micro-segmentation requires visibility across not just identity and networks, but devices, applications, workloads, and data. With that visibility comes the opportunity for analytics, to create a unified cybersecurity picture. Automation and orchestration can streamline security operations, and improve governance by applying relevant regulations and reporting requirements.
Closing Remarks:












