Zero-Trust Strategies Boost CMS and VA Security Controls - zero-trust strategies
Zero-Trust Strategies Boost CMS and VA Security Controls

Zero-trust strategies help CMS and the Department of Veterans Affairs improve visibility and control over vast amounts of sensitive data. The Centers for Medicare & Medicaid Services (CMS) manages health coverage for more than 160 million people, processing over a billion Medicare claims annually. With this massive volume of protected health information and personally identifiable data, CMS has adopted zero-trust protocols to secure its infrastructure. Wade Zarriello, acting director of the Infrastructure and User Services Group at CMS, said the agency focuses on maintaining public trust through secure data access.

CMS structures its zero-trust approach around four layers: device, network, application and data. A key initiative involves an enterprise identity, credential and access management program that consolidates disparate identity systems into a central repository. Tim Morrow, situational awareness technical manager at Carnegie Mellon University’s CERT Division, noted that integrating these systems is difficult. Organizations often struggle to integrate identity access tied into cloud providers like Amazon Web Services or Google with specific applications. Federating these services into a consistent picture is a significant step in the zero-trust journey.

Related: RFID helps US hospitals cut supply shortages

The agency is also centralizing data logging in its security incident and event management tools. This shift gives CMS consistent threat analysis across all ecosystems rather than a siloed approach where different organizations use different tools. Jason Garbis, co-chair of the Zero Trust Working Group for the Cloud Security Alliance, pointed out that zero trust reduces the volume of unexpected activity needing triage. By moving to a “default deny, explicit allow” model, operations teams spend less time investigating false positives and more time on necessary investigations.

Implementing these controls often restricts the network access developers traditionally enjoyed. CMS turned to Zscaler to solve this problem. Developers can no longer spin up an environment in the cloud and access a subnet without specific actions. Zarriello explained that adding access or permissions now requires explicit authorization under the zero-trust networking model. This change has increased operational oversight but required more team members to effectuate access.