Employees at Munson's Pickles now use personal laptops and phones on home networks to reach SaaS applications that no longer sit behind the corporate firewall. The leadership team asks why the security strategy has moved its centre of gravity from the network edge to identity. Which explanation is the most accurate?
- A.
SaaS providers assume full responsibility for access control, so the customer only needs to manage identities
- B.
Network firewalls can no longer inspect encrypted traffic, so network controls provide no security value
- C.
Identity is the one consistent control plane across every user, device, application, and network, so it becomes the primary security perimeter
- D.
Identity controls replace the need for device management and data protection, simplifying the control set
Show answer
Answer: C
Identity is the only control plane present in every access request regardless of device, network, or hosting location, which is why it becomes the primary perimeter.
- A. Shared responsibility keeps accounts, identities, data, and devices with the customer even in SaaS, so the provider does not own access control.
- B. Network controls retain value in defense in depth and form one of the seven Zero Trust pillars; the claim that they provide none is false.
- C. Identity is present in every access request regardless of network or hosting model, making it the consistent control plane and the primary perimeter.
- D. Identity controls complement rather than replace device management and data protection, which remain separate Zero Trust pillars.
