Repository logo
Research Outputs
Projects
People
Statistics
  1. Home
  2. HSG CRIS
  3. HSG Publications
  4. Sicherheitsarchitekturen im Zeitalter von Zero Trust mit Fokus auf End-User
Details

Sicherheitsarchitekturen im Zeitalter von Zero Trust mit Fokus auf End-User

Type
work report
Date Issued
2025-08-04
Author(s)
Peter Rohner  
;
Joshua Auf der Maur
;
Sina Rohner
Research Team
CC BIE
Abstract
Zero Trust (ZT) is becoming increasingly important, but so far there is little empirical evidence on its concrete implementation in Swiss companies. This study examines how large organizations are embedding key ZT elements such as digital identities, authentication, authorization, endpoint security, qualified electronic signatures, and encryption, and which measures have already been implemented or are planned.
Unlike ZT, the previous perimeter-based security model is not adequate for an increasingly networked and cloud-based world. This study makes it clear that the paradigm shift toward ZT has a profound impact on how large Swiss organizations handle essential cyber security measures in the area of end users and end points (front end).

In the context of cybersecurity, organizations are increasingly recognizing that
• with ZT, identity becomes the central security element,
• IAM systems are an essential prerequisite for implementing ZT,
• context-sensitive, continuous authentication with MFA is increasingly seen as a necessary standard, also in order to be able to use SSO securely for user-friendly authentication,
• the relevance of protecting endpoints is receding into the background, but the level of trust in digital identities is coming to the fore,

• Security risks are minimized through continuous verification of identity-based and conditional access conditions, which are combined as MFA.
• Home offices (e.g., via VDI) and BYOD pose less of a challenge in a ZT environment because access is no longer primarily controlled via the endpoint, but rather on a context-based basis.
Consistent data encryption is another key component of a ZT architecture. However, the study shows that many organizations do not yet have a mature data classification system in place. With the increased use of cloud services such as M365, the establishment of such mechanisms is becoming increasingly important.
It is clear that organizations that recognize ZT as a strategically relevant issue and allocate appropriate resources also strive for a higher level of technical maturity and are therefore able to implement ZT more consistently.
ZT is much more than a technology-driven project. It is a new security paradigm that requires strategic anchoring in management. The implementation of ZT requires the design of a new security architecture.
Abstract (De)
Zero Trust (ZT) gewinnt zunehmend an Bedeutung, doch bislang liegen nur wenige empirische Erkenntnisse zur konkreten Umsetzung in Schweizer Unternehmen vor. Diese Studie untersucht, wie grosse Organisationen zentrale ZT-Elemente wie digitale Identitäten, Authentisierung, Autorisierung, End-Point Security, qualifizierte elektro-nische Signatur und Verschlüsselung verankern und welche Massnahmen bereits um-gesetzt oder geplant sind.
Im Gegensatz zu ZT wird das bisherige perimeterbasierte Sicherheitsmodell einer zu-nehmend vernetzten und cloudbasierten Welt nicht gerecht. Die vorliegende Studie macht deutlich, dass der Paradigmenwechsel hin zu ZT tiefgreifende Auswirkungen auf die Art und Weise hat, wie grosse Schweizer Organisationen wesentliche Mittel der Cyber Security im Bereich von End-User und End-Point (Frontend) handhaben.
Organisationen erkennen im Kontext von Cyber Security zunehmend, dass
• mit ZT die Identität zum zentralen Sicherheitselement wird,
• IAM-Systeme eine wesentliche Voraussetzung für die Umsetzung von ZT sind,
• kontextabhängige, kontinuierliche Authentisierung mit MFA zunehmend als notwendiger Standard angesehen wird, auch um SSO für eine nutzerfreundli-che Authentisierung sicher einsetzen zu können,
• die Relevanz des Schutzes von End-Points in den Hintergrund tritt, dafür aber das Vertrauensniveau von digitalen Identitäten in den Vordergrund rückt,
• durch eine kontinuierliche Überprüfung von identitätsbasierten und Conditio-nal Access Bedingungen, die als MFA kombiniert werden, Sicherheitsrisiken mi-nimiert werden,
• Homeoffice (z.B. über VDI) und BYOD in einer ZT-Umgebung eine geringere Herausforderung darstellen, weil Zugriffe nicht mehr primär über den End-Point, sondern kontextbasiert gesteuert werden.
Konsequente Verschlüsselung von Daten stellt ein weiterer zentraler Baustein einer ZT-Architektur dar. Allerdings zeigt die Studie, dass viele Organisationen noch über kein ausgereiftes Datenklassifikationssystem verfügen. Im Zuge der verstärkten Nutzung von Cloud-Diensten, wie M365, gewinnt die Etablierung solcher Mechanismen an Rele-vanz.
Es zeigt sich, dass Organisationen, die ZT als strategisch relevantes Thema anerkennen und entsprechende Ressourcen bereitstellen, auch einen höheren technischen Reifegrad anstreben und damit ZT konsequenter umsetzen können.
ZT ist weit mehr als ein technologiegetriebenes Projekt. Es handelt sich um ein neues Sicherheitsparadigma, welches eine strategische Verankerung im Management erfor-dert. Für die Umsetzung von ZT bedarf es der Konzeption einer neuen Sicherheitsarchitektur.
Language
German
Keywords
Digital Transformation
Cyber Security
Zero Trust
HSG Classification
contribution to practical use / society
URL
https://www.alexandria.unisg.ch/handle/20.500.14171/123226
Subject(s)

information managemen...

Division(s)

IWI - Institute of In...

Contact Email Address
peter.rohner@unisg.ch
File(s)
Thumbnail Image

open.access

Name

Studie IWI-HSG_Sicherheitsarchitekturen im Zeitalter von Zero Trust mit Fokus auf End-User.pdf

Size

1.21 MB

Format

Adobe PDF

Checksum (MD5)

5333135f1b8128a16cea4839313fc9b6

Support
HSG researchers can find instructions here for adding or importing publications (DOI, ORCID). Please send questions to alexandria@unisg.ch

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Accessibility settings
  • Privacy policy
  • End User Agreement
  • Send Feedback
Repository logo COAR Notify