Modernizing Legacy VPN Architectures through Zero Trust Access Models
Main Article Content
Abstract
Historically, Legacy Virtual Private Network (VPN) Architectures have been employed by agencies for remote access. Nevertheless, because of the shortcomings of such architecture, their efficacy in countering cyber security attacks becomes compromised, as they rely on the trust model and are susceptible to lateral movements once the perimeter is breached. In order to overcome this problem, guidelines require the implementation of the Zero Trust Architecture (ZTA) by agencies. This paper employs an exploratory approach based on secondary document analysis of policies, maturity models, technical papers, and case studies, which are used for understanding the issues involved in the adoption of Zero Trust Architecture in organizations, along with their outcomes and trends. Organizational readiness, involving workforce resistance and training issues, was identified as an important but underappreciated variable impacting migration success. The analysis reveals the importance of taking a coordinated approach towards Zero Trust adoption, as it requires advancement on multiple fronts rather than mere technological enhancement. The findings provide insight into the complex nature of the challenges associated with implementing Zero Trust within agencies, underscoring the need for a holistic approach.