This week I will be leading the discussion post on the trend of Continuous Adaptive Risk and Trust.
The first question to answer is what is Continuous Adaptive Risk and Trust (CARTA)? "CARTA builds on Gartner's Adaptive Security Architecture to shift security and risk management processes away from single allow/deny gating to more agile, context-aware and adaptive methods" (Ford, 2019). It is simply a process of approaching security of a system or enterprise. Traditional information security efforts rely on detecting attacks through passive means and responding to them to halt an attack (Danova, 2018). The CARTA strategy instead requires continuous discovery, monitoring, and assessment while including both adaptive attack and access protection (Ford, 2019). CARTA can be seen as a proactive approach to security instead of the reactive approach that traditional security often takes. Similar to the System Development Life Cycle, CARTA is a continuous approach. Each phase leads into the next and is never ending. Below is an image of the CARTA cycle for visual understanding.