SESSION ID:SESSION ID:
#RSAC
Heather Adkins
BeyondCorp -
How Google Protects Its Corporate
Security Perimeter without Firewalls
TECH-T11
Director of Security
Google
Rory Ward
Site Reliability Engineering Manager
Google
#RSAC
Story time
#RSAC
How your Enterprise is probably set up
#RSAC
A convergence of issues
4
#RSAC
WALLS
WORK
DON’T
Google’s realization ...
WALLS DON’T
WOR
K
#RSAC
A different approach
#RSAC
BeyondCorp Principles ...
#1 Connecting from a particular network must not determine which
services you can access.
#RSAC
BeyondCorp Principles ...
#2 Access to services is granted based on what we know about
you and your device.
#RSAC
BeyondCorp Principles ...
#3 All access to services must be authenticated, authorized
and encrypted.
#RSAC
Our Six Year Mission
To have every Google employee
work successfully from untrusted networks
without use of a VPN.
#RSAC#RSAC
Implementing BeyondCorp
How we did it and guidelines for how you can do it.
#RSAC
High Level
Access
Proxy
Single
Sign On
Access
Control
Engine
User
Inventory
Device
Inventory
Trust
Repository
#RSAC
Get intimate with your Users
User Inventory
#RSAC
Get intimate with your Devices
Device Inventory
#RSAC
Build a Dynamic Trust Repository
Trust
Repository
#RSAC
Build and Enforce Access Policy
Access
Control
Engine
User
Inventory
Device
Inventory
Trust
Repository
#RSAC
Enable Access from anywhere
Access
Proxy
Access
Control
Engine
Single
Sign On
#RSAC#RSAC
Migrating to BeyondCorp
How we did it and guidelines for how you can do it.
#RSAC
Migrating to BeyondCorp
#RSAC
Deploy an Unprivileged Network
#RSAC
Analyse our Traffic
#RSAC
Safely Migrate Devices
#RSAC#RSAC
Outreach
Telling the broader community about BeyondCorp
#RSAC
BeyondCorp described to the Industry
#RSAC#RSAC
Lessons Learned
What six years has taught us
#RSAC
Lessons Learned
• Get, and retain, executive
support.
#RSAC
Lessons Learned
• Data Quality is key.
#RSAC
Lessons Learned
• Enable Painless Migration.
#RSAC
Lessons Learned
• Clear User Communications.
#RSAC
Lessons Learned
• Run Highly Reliable Systems.
#RSAC
Applying BeyondCorp
1. Have zero trust in your network.
2. Base all access decisions on what you know about the user and
their device.
3. Migrate carefully so as not to break existing users.
#RSAC
Questions and Answers ...

How Google Protects Its Corporate Security Perimeter without Firewalls