<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/c4isrnet/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>C4ISRNet - Media for the Intelligence-Age Military | C4ISRNET</title>
	<atom:link href="https://one.sightlinemg.com/c4isrnet/advertiser/palo-alto-networks/feed/" rel="self" type="application/rss+xml" />
	<link>https://one.sightlinemg.com/c4isrnet/</link>
	<description>Media for the Intelligence-Age Military &#124; C4ISRNET</description>
	<lastBuildDate>Sat, 08 Aug 2026 18:18:57 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-c4i.png?w=32</url>
	<title>C4ISRNet - Media for the Intelligence-Age Military | C4ISRNET</title>
	<link>https://one.sightlinemg.com/c4isrnet/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331819</site>	<item>
		<title>Accelerating the Zero Trust Journey in Federal Government</title>
		<link>https://one.sightlinemg.com/c4isrnet/native/palo-alto-networks/accelerating-the-zero-trust-journey-in-federal-government/</link>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 29 Jun 2022 16:13:13 +0000</pubDate>
				<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/native/uncategorized/accelerating-the-zero-trust-journey-in-federal-government/</guid>

					<description><![CDATA[Zero Trust is a strategic approach to cybersecurity that secures an organization by eliminating implicit trust and continuously validating every stage of digital interaction. It’s a way for government agencies and departments to build resilience into their IT environments. The Zero Trust Model has become increasingly important for the federal government due to President Biden’s [&#8230;]]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18884</post-id><news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Zero Trust is a strategic approach to cybersecurity that secures an organization by eliminating implicit trust and continuously validating every stage of digital interaction. It’s a way for government agencies and departments to build resilience into their IT environments.</p>



<p class="wp-block-paragraph">The Zero Trust Model has become increasingly important for the federal government due to President Biden’s unprecedented Executive Order on Improving the Nation’s Cybersecurity and the more recent federal Zero Trust architecture strategy from the U.S. Office of Management and Budget (OMB).</p>



<p class="wp-block-paragraph">Palo Alto Networks has been helping the federal government move toward Zero Trust for several years through our work directly with agencies and as part of the NIST National Cybersecurity Center of Excellence.</p>



<h3 class="wp-block-heading">Zero Trust Today: A Modern Security Approach for Federal Government</h3>



<p class="wp-block-paragraph">In today’s environment, federal departments and agencies have reached a tipping point: many users and apps now reside outside of the traditional perimeter. A hybrid workforce is a new reality. Departments and agencies must provide access from anywhere and deliver an optimal user experience.</p>



<h3 class="wp-block-heading">The Zero Trust Enterprise: Making Zero Trust Actionable</h3>



<p class="wp-block-paragraph">The biggest challenge to adopting a Zero Trust approach is not a lack of specific security tools but rather a simple lack of resources (talent, budget, interoperability, time, etc.). Through Palo Alto Networks extensive experience and comprehensive set of security capabilities, the Zero Trust Enterprise introduces consistent Zero Trust controls across the entire organization.</p>



<h3 class="wp-block-heading">A Trusted Partner: More Than a Decade of Zero Trust Experience</h3>



<p class="wp-block-paragraph">With thousands of customers and deployments, Palo Alto Networks is a Zero Trust pioneer with experience across the entire security ecosystem, including network, endpoint, Internet of Things (IoT), critical infrastructure and more. Here’s what makes our Zero Trust Enterprise approach different:</p>



<ul class="wp-block-list"><li>Comprehensive: Zero Trust is a methodology and should never focus on a narrow technology. Instead, it should consider the full ecosystem of controls that many organizations rely on for protection.</li><li>Actionable: Comprehensive Zero Trust isn’t easy, but getting started shouldn’t be hard. For example, begin with what you have. Think about what current set of controls can be implemented using the security tools you have in place today.</li><li>Intelligible: Your Zero Trust approach should be easy to convey to both nontechnical and technical leaders in a concise, easy-to-understand summary.</li><li>Ecosystem friendly: In addition to having one of the most comprehensive portfolios in the market, Palo Alto Networks and its broad ecosystem of security partners have an unparalleled ability to make your Zero Trust journey a reality.</li></ul>



<h3 class="wp-block-heading">A Comprehensive Zero Trust Approach: Users, Applications and Infrastructure</h3>



<p class="wp-block-paragraph">At its core, Zero Trust is about eliminating implicit trust across the organization. This means eliminating implicit trust related to users, applications and infrastructure.</p>



<ul class="wp-block-list"><li>Users: Applying Zero Trust to users is a key step in any Zero Trust effort. It starts with strong identity controls that must be continually validated for every user, using best practices, such as multifactor authentication and just-in-time access.</li><li>Applications: Cloud transformation provides strategic advantages for government agencies and departments. It enables new cloud native application development practices and faster application rollout.</li><li>Infrastructure: Research shows that on average, an organization runs 45 cybersecurity-related tools on their network.¹ This heterogeneous environment means that IT teams often have poor visibility and control over unmanaged resources, such as IoT devices and supply chain infrastructure.</li></ul>





<p class="wp-block-paragraph">For each of the three pillars – users, applications and infrastructure – it is critical to consistently take the following actions:</p>



<ul class="wp-block-list"><li>Establish identity using the strongest authentication possible.</li><li>Verify the device/workload. Identifying laptops, servers, personal smartphones or mission-critical IoT devices that are requesting access, determining the device’s identity and verifying its integrity are all integral to Zero Trust.</li><li>Secure the access. Agencies must ensure that users only have access to the minimal amount of resources needed to conduct an activity.</li><li>Secure all transactions.</li></ul>



<h3 class="wp-block-heading">The Security Operations Center: An Essential Function</h3>



<p class="wp-block-paragraph">The security operations center (SOC) continuously monitors all activity for signs of anomalous or malicious intent to provide an audit point for earlier trust decisions and potentially override them if necessary.</p>



<p class="wp-block-paragraph">Read more on accelerating your Zero Trust journey: <a href="https://www.paloaltonetworks.com/resources/whitepapers/accelerating-your-zero-trust-journey-in-public-sector" target="_blank">https://www.paloaltonetworks.com/resources/whitepapers/accelerating-your-zero-trust-journey-in-public-sector</a></p>



<p class="wp-block-paragraph">___________________________________________________________________________________________</p>



<p class="wp-block-paragraph">¹ <a href="https://www.zdnet.com/article/the-more-cybersecurity-tools-an-enterprise-deploys-the-less-effective-their-defense-is/" target="_blank">The More Cybersecurity Tools an Enterprise Deploys, the Less Effective Their Defense Is</a></p>
]]></content:encoded>
	</item>
		<item>
		<title>Preparing for 5G: A Security Primer for Federal Agencies</title>
		<link>https://one.sightlinemg.com/c4isrnet/native/palo-alto-networks/preparing-for-5g-a-security-primer-for-federal-agencies/</link>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 18 Jan 2022 19:41:11 +0000</pubDate>
				<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/native/uncategorized/preparing-for-5g-a-security-primer-for-federal-agencies/</guid>

					<description><![CDATA[The Department of Defense (DoD) and agencies across the US federal government are preparing for 5G connectivity. With the promise of fast speeds, lower latency and stronger authentication mechanisms, 5G powered networks present significant new benefits and exciting possibilities. Agencies’ internal network teams, contractors, or traditional service providers will adopt private 5G subscriptions to run [&#8230;]]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">28212</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1306156001.jpg.jpg" width="6000" height="4000" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">The Department of Defense (DoD) and agencies across the US federal government are preparing for 5G connectivity. With the promise of fast speeds, lower latency and stronger authentication mechanisms, 5G powered networks present significant new benefits and exciting possibilities. Agencies’ internal network teams, contractors, or traditional service providers will adopt private 5G subscriptions to run small cells where needed—for example, on a military base, an agency campus, or even a ship. These 5G networks will accelerate exponential growth of connected Internet of Things (IoT) devices, which will be increasingly integrated into defense infrastructure.</p>



<p class="wp-block-paragraph">As we approach this new frontier, the security of any new 5G network must be factored in from the start. 5G will require at least the same level of protection that we have seen for years across more traditional agency IT networks through practices like implementing a security operations center (SOC), proper asset management, and continuous monitoring. Augmenting these practices with modernized approaches like Zero Trust and automation will enable agencies to harness the power of 5G safely and for the long term.</p>



<h1 class="wp-block-heading">Applying 5G’s Advanced Features</h1>



<p class="wp-block-paragraph">Multiple new features make 5G a quantum leap forward in capabilities.</p>



<h4 class="wp-block-heading"><b>Network Slicing</b></h4>



<p class="wp-block-paragraph">One of 5G’s most powerful new capabilities is network slicing, a way to virtualize the 5G network into segments utilizing software-defined networking (SDN). Network slicing ensures high network performance, reliability, and speed for a breadth of applications and devices. It enables advanced capabilities such as:</p>



<p class="wp-block-paragraph">• <b>Enhanced Mobile Broadband (eMBB) </b>for high data transfer rates across a wide coverage area</p>



<p class="wp-block-paragraph">• <b>Ultra-Reliable Low-Latency Communication (URLLC) </b>to support mission-critical applications (e.g., smart grid) that need extremely high speed and reliability</p>



<p class="wp-block-paragraph">• <b>Massive Internet of Things (MIoT) </b>to support many IoT devices in a small area</p>



<p class="wp-block-paragraph">Importantly, network slicing will allow network traffic from purpose-built devices (e.g., drones, telehealth devices, weapons systems) to be prioritized over traffic from lower priority devices like mobile phones and laptops.</p>



<h3 class="wp-block-heading">Wired Replacement</h3>



<p class="wp-block-paragraph">Wired replacement will enable a vastly increased level of continuous connectivity for mobile users and devices moving throughout 5G-enabled environments. By replacing traditional network jacks or more limited wireless networks, 5G cells installed in a building, campus, ship, or aircraft will offer highly flexible and continuous connectivity for users and the growing number of IoT devices. 5G will provide far more net- work throughput and stability beyond current 3G and 4G networks, delivering more reliable performance and connection to applications, the cloud, and the internet.</p>



<h3 class="wp-block-heading">Multi-Access Edge Computing</h3>



<p class="wp-block-paragraph">Multi-access edge computing (MEC) represents an evolution in distributed computing, accelerating information processing so that sensors and IoT devices will be collecting vast amounts of data in need of fast analysis. Acting as kind of a localized private data center, edge computing utilizes containerized analytics applications running on limited hardware at the edge for real-time analysis. Bypassing the transmission of data to remote or cloud-based environments eliminates latency and enables faster decision-making.</p>



<p class="wp-block-paragraph">Consider, for example, the potential at a 5G-connected Air Force base. Whenever a plane lands, a manually intensive process is required to inspect its integrity for the next flight and replace any faulty components that, if not in stock at the base, must be ordered from a centralized distribution center. Connecting to the aircraft through 5G will enable automatic safety validation checks upon landing, quickly flagging any issues for the engineering team to remediate. Further, connecting parts replenishment requirements into logistics systems can enable automatic ordering as well as tracking of shipping and delivery information.</p>



<h3 class="wp-block-heading">Ubiquitous Connectivity</h3>



<p class="wp-block-paragraph">Federal networks can provide access to a wide range of users and classification levels known as multi-domain support. This model is used to impose role-based controls for different types of information accessed through the network (e.g., unclassified, public trust, confidential, secret, and top secret). 5G can enable strict segmentation while ensuring broad and ubiquitous connectivity across all network users’ classification levels, regardless of device type.</p>



<p class="wp-block-paragraph">To continue our connected Air Force base example, the isolated network connecting the airplane diagnostic system should be able to connect well beyond the aircraft being analyzed, to other Air Force networks (logistics, purchasing, etc.) or even other DoD environments. That broad connectivity requires network segmentation, enabled by 5G’s network slicing capability, to ensure multi-domain use cases are securely supported.</p>



<h1 class="wp-block-heading">5G’s Escalated Security Demands Parallel Traditional Network Requirements</h1>



<p class="wp-block-paragraph">All known federal use cases and many more to unfold hold great promise, but also a greatly increased level of risk. Today, far more capabilities are being vested in technology than ever, over open radio waves rather than closed networks.</p>



<p class="wp-block-paragraph">Network attacks frequently target the physical infrastructure of the packet core. Protecting 5G will demand the same level of strict controls and protections as are applied to that physical infrastructure. This requires implementing several proven practices. First is imposing accountability (part of the confidentiality, integrity, and accountability [CIA] triad), enabled through granular logging and deep visibility into encrypted tunnel traffic that is analyzed for threats.</p>



<p class="wp-block-paragraph">Next is Zero Trust access, an architectural security strategy rooted in the principle, “never trust, always verify.” Segmentation is an important part of Zero Trust, since as with traditional network access controls, 5G users should only have access to what is needed to perform their day-to-day functions. Because new connected devices will rely on analytics from the applications they work with, all network traffic will need to be segmented and prioritized to make sure the highest performance traffic has the necessary quality of service, latency, and network performance.</p>



<p class="wp-block-paragraph">Also, as with traditional networks, 5G will require determining the subscriber ID, and then applying granular controls to verify how and from where a user or device is attempting to gain network access.</p>



<p class="wp-block-paragraph">Each type of device will also need to be dynamically protected against known and unknown vulnerabilities. There will be sensors on 5G networks that still use legacy operating systems and vulnerable firmware that must be secured. Exposing those devices to 5G’s power will require deeper visibility and controls, best achieved by automating mechanisms to find device vulnerabilities as well as classify the controls needed to quickly remediate them.</p>



<p class="wp-block-paragraph">Thorough network protections will be imperative to monitor the critical infrastructure and high-risk devices agencies will be putting into 5G environments. Moreover, as 5G scales to connect more devices, human operators that run legacy SOCs won’t be able to keep up. Automation will be the only option fast and efficient enough to isolate and counter threats as quickly as they’re found.</p>



<h1 class="wp-block-heading">Palo Alto Networks: First in 5G-Native Security</h1>



<p class="wp-block-paragraph">Palo Alto Networks offers the industry’s first 5G-native security solution, enabling end-to-end security from the control plane to the user plane through the applications. This includes containerized 5G security, real-time correlation of threats to 5G identifiers, and 5G network slice security.</p>



<h3 class="wp-block-heading">Protecting Devices</h3>



<p class="wp-block-paragraph">Two primary classes of device will connect to 5G.</p>



<h4 class="wp-block-heading">End User Devices</h4>



<p class="wp-block-paragraph">End users’ mobile devices (e.g., cell phones, laptops, tablets) will not be permanently fixed on the network agencies will lose visibility and control over them at times, creating significant risk. For instance, they will likely travel beyond the boundaries of the private 5G network. They may connect to other open 5G networks or private Wi-Fi, download unsanctioned applications, or even unintentionally install malicious software. Because user behavior cannot be fully controlled, detecting and preventing threats is a requirement for securing 5G infrastructure.</p>



<p class="wp-block-paragraph">Frequently, after malware is downloaded, it attempts to propagate through the device’s network. Palo Alto Networks provides deeper visibility into the lateral movement of malware traffic traversing a firewall or segmentation gateway, correlating it to the subscriber or hardware identification number of the 5G network user so threats can be isolated and their propagation stopped.</p>



<h4 class="wp-block-heading">Internet of Things Devices</h4>



<p class="wp-block-paragraph">The other major device class that will connect to 5G is sensor-driven IoT devices. 5G allows for greater networked device density, making it the preferred IoT connectivity fabric. Many IoT devices are already installed on agencies’ networks across a spectrum of functions (even down to connected dish- washers), and many more will follow.</p>



<p class="wp-block-paragraph">These purpose-built, high-performance devices pose perhaps the biggest security threat to 5G. Typically built on small single-board computers (SBCs), they run lightweight operating systems not designed for security.</p>



<p class="wp-block-paragraph">To fill the gap, Palo Alto Networks uses network telemetry coupled with machine learning to discover each device on the 5G network and classify it according to its purpose (e.g., camera, medical device, mobile phone). Once a device has been classified, our Next-Generation Firewalls (NGFWs) recommend policies that are dynamically built to allow only normal, acceptable network behaviors of IoT devices in the same device category. Implementing security policies in the packet core allows for more accurate security for IoT devices.</p>



<h4 class="wp-block-heading">Implementing Zero Trust</h4>



<p class="wp-block-paragraph">Network slicing enables the multiplexing of virtualized and independent logical networks on the same physical network infrastructure. Each network slice is an isolated end-to-end network tailored to fulfill diverse requirements requested by a particular application. Acting as a segmentation gateway, our NGFW implements granular security specific to each network slice, ensuring security, speed, performance, low latency, and delivery for high-priority traffic. Implementing security policies per network slice allows for microsegmentation of 5G traffic. A testament to its quality, our NGFW meets the National Institute of Standards and Technology (NIST) requirements for a policy enforcement point (PEP) specified in Special Publication 800-207.¹</p>



<p class="wp-block-paragraph">An effective Zero Trust access policy requires defining what specific users or devices can access what resources using what device. Through the combination of Equipment ID and Subscriber ID with our App-ID<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" />, and Content-ID<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> technologies, Palo Alto Networks allows for granular Zero Trust policies to be defined.</p>



<p class="wp-block-paragraph">App-ID inspects the network traffic at Layer 7 to categorize the application. This allows for accuracy beyond just port and protocol when defining application access policies. Equipment ID maps international mobile equipment identity (IMEI) to network traffic, which allows policies to be built for specific types of hardware. This capability also enables agencies to build policies that, for example, only allow Government Furnished Equipment (GFE) on the network or define which applications can be accessed from mobile phones vs. IoT devices.</p>



<p class="wp-block-paragraph">The last building block of a 5G Zero Trust policy is defining who can access resources. Subscriber ID maps the international mobile subscriber identity (IMSI) to network traffic, enabling access policies to be built around the SIM card assigned to devices or individuals. Combining Subscriber ID with Equipment ID ensures that only authorized users accessing the network with a GFE device can access their needed applications. It also provides segmentation between the user and device network so that only a particular class of device that is assigned a SIM card can access IoT-specific applications.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1938" height="558" src="/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.45.54-PM.png.png" alt="" class="wp-image-80765" srcset="https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.45.54-PM.png.png 1938w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.45.54-PM.png.png?resize=300,86 300w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.45.54-PM.png.png?resize=768,221 768w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.45.54-PM.png.png?resize=1024,295 1024w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.45.54-PM.png.png?resize=1536,442 1536w" sizes="(max-width: 1938px) 100vw, 1938px" /><figcaption class="wp-element-caption">Figure 1: 5G network security slices</figcaption></figure>



<h3 class="wp-block-heading">Protecting Applications</h3>



<p class="wp-block-paragraph">Applications running on 5G networks will be hosted in a combination of the MEC, public clouds, and private clouds. Securing these applications will rely on implementing consistent security, adopting Zero Trust, and enabling DevSecOps.</p>



<p class="wp-block-paragraph">Centralized visibility and control will be mandatory. Using a single pane of glass for visibility into network traffic, asset security posture, and ongoing network events will give operators a deeper understanding of a 5G deployment’s health. What’s more, using a centralized tool to implement security across the hosting environments will ensure consistent security can be implemented and maintained.</p>



<p class="wp-block-paragraph">The Palo Alto Networks NGFW can be deployed in physical, virtual, and containerized form factors to meet the flexible needs of the varied hosting environments. Our Panorama<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> network security management solution provides centralized management to help operators implement consistent security policies across a hybrid cloud environment.</p>



<p class="wp-block-paragraph">Federal 5G networks will provide multi-domain access, host sensitive data, and provide control over mission-critical sensors. Using a Zero Trust approach to application security is the best way to ensure the confidentiality, integrity, and availability of the data, applications, assets, and services (DAAS) to accommodate differing levels of user access permissions. A Zero Trust implementation relies on granular access policies, map- ping subscribers and hardware to the DAAS. Palo Alto Networks 5G-native security allows contextual information to be taken from the user plane function and applied to segmentation policies in the MEC, private clouds, or public clouds. Instead of relying on standard segmentation approaches like IP address or username, 5G enables more granular segmentation by defining which subscribers and types of hardware can access applications, using identification methods like IMSI and IMEI.</p>



<p class="wp-block-paragraph">As federal agencies develop applications to take full advantage of 5G, shifting security into the development process through DevSecOps will go a long way to ensuring application integrity. The right security tools can provide guardrails to enable high-velocity development without any security compromise. Palo Alto Networks Prisma® Cloud Compute Edition integrates with the continuous integration tools developers use to drive automation. This best-in-class host and container security solution provides continuous monitoring of application components throughout the software development lifecycle while offering proactive protection.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="2010" height="826" src="/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.48.56-PM.png.png" alt="" class="wp-image-80767" srcset="https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.48.56-PM.png.png 2010w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.48.56-PM.png.png?resize=300,123 300w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.48.56-PM.png.png?resize=768,316 768w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.48.56-PM.png.png?resize=1024,421 1024w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.48.56-PM.png.png?resize=1536,631 1536w" sizes="auto, (max-width: 2010px) 100vw, 2010px" /><figcaption class="wp-element-caption">Figure 2: Zero Trust architecture—multi-domain network slicing and segmentation</figcaption></figure>



<h3 class="wp-block-heading">Protecting Networks</h3>



<p class="wp-block-paragraph">Attacks on the underlying infrastructure are among the larg- est threats to 5G networks. In early implementations of 5G, such attacks have largely included usage of the network and 5G protocols. The best method to stop this type of outage-causing attack is to inspect the GPRS Tunneling Protocol (both GTP-C and GTP-U) traffic and establish security visibility and control to prevent attacks, threats, and vulnerabilities (e.g., floods of traffic to packet core resources). Using App-ID, our NGFW inspects Stream Control Transmission Protocol (SCTP) traffic to detect and prevent protocol anomalies or known ex-ploits. Beyond protecting against misuse and exploitation of 5G signaling protocols, Palo Alto Networks inspects network traffic and prevents distributed denial-of-service (DDoS) attacks by dropping traffic that is overwhelming traffic patterns. Preventing attacks against the packet core is the best way to ensure availability of 5G transport.</p>



<h1 class="wp-block-heading">It Takes a Platform</h1>



<p class="wp-block-paragraph">Ultimately, no security solution is completely impervious. Combining multiple capabilities into an integrated platform is required to effectively prevent successful attacks.</p>



<p class="wp-block-paragraph">Palo Alto Networks delivers a robust security platform that provides end-to-end protection for 5G networks that will soon be running many agency mission-critical operations. Open integration will be key to securing a 5G solution.</p>



<p class="wp-block-paragraph">Our solution enables information-sharing, allowing for continuous monitoring and proactive, automated security. Our single platform, which integrates with 5G core capabilities, will help agencies ensure stability, performance, availability, and integrity of 5G infrastructure and devices.</p>



<p class="wp-block-paragraph"><a href="https://www.paloaltonetworks.com/us-federal">For more information, please visit </a><a href="https://www.paloaltonetworks.com/us-federal">paloaltonetworks.com/ us-federal</a><a href="https://www.paloaltonetworks.com/us-federal">.</a></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1746" height="870" src="/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.52.29-PM.png.png" alt="" class="wp-image-80768" srcset="https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.52.29-PM.png.png 1746w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.52.29-PM.png.png?resize=300,149 300w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.52.29-PM.png.png?resize=768,383 768w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.52.29-PM.png.png?resize=1024,510 1024w, https://one.sightlinemg.com/wp-content/uploads/2026/08/Screen-Shot-2022-01-04-at-1.52.29-PM.png.png?resize=1536,765 1536w" sizes="auto, (max-width: 1746px) 100vw, 1746px" /><figcaption class="wp-element-caption">Figure 3: Palo Alto Networks 5G architecture</figcaption></figure>



<p class="wp-block-paragraph"><i>1. “NIST Special Publication 800-207,” National Institute of Standards and Technology, August 2020, </i><a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf"><i>https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf</i></a><a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf"><i>.</i></a></p>
]]></content:encoded>
	</item>
		<item>
		<title>Simplifying Security in Multi-Cloud Environments</title>
		<link>https://one.sightlinemg.com/c4isrnet/native/palo-alto-networks/simplifying-security-in-multi-cloud-environments/</link>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 14 Apr 2021 19:11:43 +0000</pubDate>
				<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/native/uncategorized/simplifying-security-in-multi-cloud-environments/</guid>

					<description><![CDATA[Federal agencies are moving from Cloud First to Cloud Smart policies. In doing so, they have adopted one of the top Cloud Service Providers (CSPs). Most agencies already use more than one of the major cloud providers – like AWS and Microsoft – with others set to join the landscape. With this in mind, Palo [&#8230;]]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">10720</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/panw_cloud_1200x628.jpg.jpg" width="1200" height="628" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Federal agencies are moving from Cloud First to Cloud Smart policies. In doing so, they have adopted one of the top Cloud Service Providers (CSPs). Most agencies already use more than one of the major cloud providers – like AWS and Microsoft – with others set to join the landscape. With this in mind, Palo Alto Networks launched their FedRAMP-authorized Prisma Cloud Solution, offering a comprehensive security platform covering cloud-native and multi-cloud environments.</p>



<p class="wp-block-paragraph">Multi-cloud environments are clearly here to stay. Yet, there is no standardization across them. Each CSP has its own set of application programming interfaces (APIs) and mechanisms for the control and management of its services, including development. Successful DevOps across CSP platforms requires development team agility and also a new approach to security.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="726" height="314" src="/wp-content/uploads/2026/08/PANW_TL-image.jpg.jpg" alt="" class="wp-image-31818" srcset="https://one.sightlinemg.com/wp-content/uploads/2026/08/PANW_TL-image.jpg.jpg 726w, https://one.sightlinemg.com/wp-content/uploads/2026/08/PANW_TL-image.jpg.jpg?resize=300,130 300w" sizes="auto, (max-width: 726px) 100vw, 726px" /></figure>



<p class="wp-block-paragraph">One of the biggest challenges is a lack of visibility into the cloud providers themselves. It’s common for different functional teams to spin up public cloud resources into which security and operations teams lack visibility. That’s quite different from traditional data center environments where assets are inventoried when procured and can be readily tracked. Protecting virtual cloud services provisioned by distributed teams is difficult at best. When security does have visibility, they still need to manage multiple CSP consoles without having an authoritative source for all of the data.</p>



<p class="wp-block-paragraph">Another big issue is the cyber talent shortage. CSPs are innovating so quickly that it’s simply hard to keep up. Each CSP environment brings hundreds of unique configuration controls, which also frequently change. Configuring across two or three of them compounds the problem. There just aren’t many people with strong knowledge of these environments; those who have this expertise are expensive and in high demand.</p>



<p class="wp-block-paragraph">There is also the challenge of compliance across multiple cloud services. Resources deployed in the cloud still need to provide Continuous Diagnostics and Mitigation to adhere to compliance requirements like FISMA, CIS, ISO, and PCI. With so many cloud services provisioned by various teams, security professionals may not know what’s in their agency’s data “buckets.” Sensitive data making its way into misconfigured public cloud environments escalates both compliance and data breach risks. It also impacts the goal most agencies have of moving from a point-in-time Authority to Operate (ATO) to continuous ATO that addresses security requirements from the beginning of the development process.</p>



<p class="wp-block-paragraph">These challenges make clear that automation is no longer optional for keeping agencies safe. Having a single platform where multi-cloud data can be integrated provides digital guardrails for all cloud services an agency uses.</p>



<p class="wp-block-paragraph">That’s where Prisma Cloud comes in. Prisma Cloud is the only comprehensive cloud security platform covering both cloud and cloud native security. The platform provides predefined policies, advanced automation and machine learning templates that enable even security generalists to manage security across cloud environments. That’s far more efficient and cost-effective than needing expensive, hard-to-find subject matter experts.</p>



<p class="wp-block-paragraph"><b>Shifting-Left and Implementing IaC/CaC</b></p>



<p class="wp-block-paragraph">Federal agencies develop and run some of the most complex and mission-critical applications. To do so requires deploying a large breadth of code into cloud environments: applications, storage configurations, user management, or even the entire infrastructure.</p>



<p class="wp-block-paragraph">Developers often turn to infrastructure as code (IaC) tools to automate the creation of cloud environments. While it is efficient to quickly bring infrastructure up in a new cloud environment or region when needed, it’s also easy to make mistakes. Our research indicates that many developers don’t fully understand the IaC templates they download from the commonly used GitHub platform. That can lead to misconfigured cloud infrastructure by spreading configurations that were weak to begin with. Palo Alto Networks believes this is such a big problem that we recently acquired Bridgecrew, a company that offers the&nbsp;<a href="https://www.checkov.io/">Checkov</a>&nbsp;open-source tool for developers to scan templates so errors can be readily corrected.</p>



<p class="wp-block-paragraph">CSPs operate under a shared responsibility model, where they secure the services they run, but customers own security for applications and configuration settings. New CSP customers often fail to understand their role in this model. In fact, Palo Alto Networks Unit 42 Cloud&nbsp;<a href="https://unit42.paloaltonetworks.com/cloud-threat-report-intro/">Threat Risk Report</a>&nbsp;noted that at least 90% of all cloud breaches result from misconfigurations. Given the complexities, Gartner predicts¹ that “through 2025, 99% of cloud security failures will be the customer’s fault.”</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="784" height="366" src="/wp-content/uploads/2026/08/PANW_TL_image-2.jpg.jpg" alt="" class="wp-image-31824" srcset="https://one.sightlinemg.com/wp-content/uploads/2026/08/PANW_TL_image-2.jpg.jpg 784w, https://one.sightlinemg.com/wp-content/uploads/2026/08/PANW_TL_image-2.jpg.jpg?resize=300,140 300w, https://one.sightlinemg.com/wp-content/uploads/2026/08/PANW_TL_image-2.jpg.jpg?resize=768,359 768w" sizes="auto, (max-width: 784px) 100vw, 784px" /><figcaption class="wp-element-caption">Prisma Cloud Protects Agencies in the CSP Shared Responsibility Model</figcaption></figure>



<p class="wp-block-paragraph">Cloud can rapidly scan the code and apply it against established security benchmarks and compliance frameworks, ensuring security standard adherence before code is ever executed. As a result, security no longer slows delivery of new capabilities to the warfighter. What’s more, the number of risks that could get into production and be exploited by enemies is considerably reduced.</p>



<p class="wp-block-paragraph"><b>Streamlining Cloud Identity and Entitlement Management (CIEM)</b></p>



<p class="wp-block-paragraph">Identity management has been a challenge since the beginning of the computer age. Using multiple CSPs compounds that challenge. CSPs can have literally hundreds of configuration options for a specific user or role, creating many opportunities for things to be<a href="https://unit42.paloaltonetworks.com/iamfinder/"> </a><a href="https://unit42.paloaltonetworks.com/iamfinder/">deployed incorrectly</a>.</p>



<p class="wp-block-paragraph">For instance, a given user may not have access to a particular cloud resource, but might later be assigned a role requiring it. Understanding permissions in CSP environments to make the permission change is very challenging. The complexity also makes it difficult to adhere to a least-privileged model. Instead, Prisma Cloud automates user permission identification, helping agencies adhere to least privilege and know exactly which users can access which resources.</p>



<p class="wp-block-paragraph">Practically speaking, it’s nearly impossible to use native tooling or disparate point products to sync policies and overcome the operational burden of securing different clouds and cloud services. Prisma Cloud provides a single platform that streamlines multi-cloud security, providing the breadth of capabilities that complex CSP management demands.</p>



<p class="wp-block-paragraph">For more information about Prisma Cloud from Palo Alto Networks,&nbsp;<a href="https://www.paloaltonetworks.com/prisma/cloud">click here.</a></p>
]]></content:encoded>
	</item>
	</channel>
</rss>
