Does data classification have to evolve?
In the modern defence and intelligence environment, it can be a struggle to decide at what level data should be protected. On the face of it, geolocation data on mobile devices should be a simple process, but for deployed military units or any organisation whose business operations are sensitive, think CNI, complexities very quickly arise. The originating system is usually OFFICIAL, but the data can become tactically sensitive depending on the time and context. From there, the information generated by this OFFICIAL device is elevated to SECRET, and the information then requires handling as such and cannot be viewed on the OFFICIAL system that generated it. Our processes and thinking need to change.
Grey areas, such as this example, bring delays, inconsistent enforcement of policy, and the likelihood of data being under- or over-classified. This either makes the data too available or not available at all to those who need it. In the days of largely human-enacted data classification, it was possible to simplify and streamline the process and apply common sense. In the modern era, Cross Domain Security (CDS) systems that can handle highly granular classifications and handling instructions, and enforce access policies, without any new classifications appearing to the end user, are critical. This was the genesis for Nexor’s Protean: the need for a more dynamic and context-aware data handling approach.
Proposed concept: New data handling instructions utilising dynamic access control
A conceptual solution could be the introduction of technical handling markers; currently, markers such as “SENSITIVE” do not add any technical controls. They simply imply that extra care should be taken when handling without providing the necessary control instructions. Introducing something like “OFFICIAL-GEO”, specifically for time-sensitive geolocation data, with stated technical controls to limit who can see it would be advantageous. No re-engineering of existing human visible classification structures would be needed.
Software Defined Networks (SDN) could make this possible using Attribute-Based Access Control (ABAC) and Data-Centric Security (DCS)[2] incorporated into a Zero-Trust Architecture (ZTA). These solutions are already in place with providers such as Okta, Palo Alto and CrowdStrike.
Beginning with this proposed solution, ABAC policies could be applied based on:
User role and security clearance;
Mission context and environmental factors (geography, time, threat level);
Metadata attached to the data (source, sensitivity, lifespan).
If we apply those policies to a typical scenario, then it might look like the mission threads outlined below:
A patrol crosses into a geo-fenced sensitive area; this triggers a change to data visibility policy, OFFICIAL access is blocked, only users with OFFICIAL-GEO ABAC attributes can view the data;
As the context shifts, policies could adapt in real time, removing the burden of manually reclassifying or distributing the data. (In reality, removing the need to over-classify to SECRET with all the overheads, cross domain issues and reduced availability this entails).
So, how does a Software Defined CDS solve this challenge
Protean is Nexor’s Software Defined (SD) CDS solution. It supports dynamic SD security environments and delivers:
Collaborative Working Environments (CWEs) using policy-driven trust relationships;
Dynamic, software-defined security zones enforcing internal trust boundaries, not just at the edge as is traditional;
Containerised multi-level security zones that are software rather than hardware enforced;
ABAC policy enforcement based on real-time user and data attributes;
Secure portals leveraging Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Token-based Authentication, ensuring continuous verification.
Nexor Protean can support potential new technical markers such as the concept of OFFICIAL-GEO without alteration to enterprise-wide classification structures. More importantly, these changes can be made quickly and deployed rapidly.
A fully developed Protean Environment also acts as a Zero Trust-aware CDS, enforcing granular access rules without extra burden on users, resulting in content becoming more appropriately protected and reducing the volume of data requiring higher classification infrastructure.
Shifting to a Complex at the Centre ~ Simple at the Edge mindset
With this architecture, new niche handling instructions such as OFFICIAL-GEO, OFFICIAL-ISR, OFFICIAL-HUMINT or a host of other possibilities, can be:
Interpreted and enforced by the CDS;
Invisible to general users, only the CDS sees and processes these new markers; the end user continues to see OFFICIAL, SECRET, TOP SECRET;
Dynamically applied at the point of access, only authorised content is delivered based on real-time policy evaluation.
This simplifies data workflows for users leaving advanced enforcement, logging, and control to be handled at the Centre where there is more compute and storage. This aligns with ZTA’s principle of “never trust, always verify.”
Visualising the Benefits
In a Protean based implementation delivering this model, significant game changing operational and strategic value is possible:
Zero Trust enforcement across domains: Every access request explicitly verified;
Policy-driven agility: Access on contextual grounds tailored to mission requirements;
User simplicity, system intelligence: The CDS does the heavy lifting, end users have no extra burden;
Cost-effective and scalable: SD controls reduce or remove the requirement for hardware-intensive SECRET environments;
Auditing and assurance: Continuous access validation assists in governance and compliance.
The benefits map below illustrates how a fully realised Protean implementation benefits a high assurance organisation.
Conclusion
Across its existing deployments, Nexor’s Protean demonstrates its ability to become a foundational enabler of Zero Trust principles in complex cross-domain environments. Combining Attribute-Based Access Control, Data-Centric Security, and containerised enforcement zones, Protean allows defence and intelligence agencies to better handle data of all classifications and addresses the gaps and grey areas between OFFICIAL and SECRET. It resolves these challenges securely, dynamically, and with minimum disruption to the end-user.
This approach aligns with the future of secure operations: trust nothing, verify everything, and deliver the right data to the right user. We are already helping our customers achieve secure Collaborative Working Environments in these demanding environments.
If you would like to talk to Nexor about how Protean can be employed by your organisation to develop a Zero-Trust Architecture, or simply to reduce the hardware burden of your current systems, or if you would like to arrange consultancy with one of our many subject matter experts, please use any of the contact methods from our contact us tab on the webpage.