Zero-Trust Strategies Sharpen Federal Agency Oversight - zero-trust security
Zero-Trust Strategies Sharpen Federal Agency Oversight

The Centers for Medicare & Medicaid Services processes over a billion Medicare claims a year, and it’s responsible for health coverage for more than 160 million people — nearly one in two Americans. That scale makes the agency’s long-running push into zero-trust security a practical necessity rather than a theoretical exercise.

“We process over a billion Medicare claims a year,” says Wade Zarriello, acting director of the Infrastructure and User Services Group at CMS. “So, access to our data needs to be secure. Maintaining public trust that we have secure data is important. Zero trust is really the system that gets us there.”

Identity Management at the Center of CMS’s Approach

CMS structures its zero-trust work around four layers: device, network, application and data. One of the agency’s most significant initiatives is an enterprise identity, credential and access management (ICAM) program designed to consolidate the various identity systems scattered across the agency into a central repository.

Related: AI Helps Companies Fill Talent Gaps Without Hiring

Tim Morrow, situational awareness technical manager in the CERT Division of the Software Engineering Institute at Carnegie Mellon University, notes that federating these services is a major payoff. Cloud providers each have their own identity tools, and applications often carry their own access controls too. Pulling those together into a consistent picture is genuinely difficult, but it’s a core step in any zero-trust journey.

CMS is also rolling out endpoint detection and response tools and network security upgrades. The agency has centralized its data logging in security incident and event management platforms, which gives it a single view of threat activity across all its systems. Zarriello says this replaced a fragmented approach where different parts of the organization ran their own analysis with separate tools.

One benefit that tends to get overlooked, according to Jason Garbis, co-chair of the Zero Trust Working Group for the Cloud Security Alliance, is the reduction in unexpected log and network activity. When access shifts to a “default deny, explicit allow” model, there’s simply less access to evaluate, which frees up operations teams to focus on investigations that actually matter.

Related: Cigna pumps $100M into AI pharmacy tech

The transition hasn’t been smooth in every area. Developers working on CMS projects, both internal staff and outside partners, used to enjoy wide-open network access. Zero trust doesn’t allow that anymore. The agency turned to Zscaler to manage the problem, meaning developers now get access only to specific applications or segments they need.

“Developers can no longer spin up an environment in the cloud, assign an IP address and just have access to whatever else is within that subnet,” says Zarriello. “There have to be specific actions in order to add access or add permissions to that asset.”

Zero Trust and CTEM Reinforce Each Other

Both agencies are pairing zero trust with continuous threat exposure management (CTEM), a framework for continuously identifying, validating and prioritizing risks. The two approaches tackle the same problem from different angles.

Related: Health Data Misuse Sparks Public Concern

Zarriello sees them as complementary by design. Zero trust is the enforcement layer, while CTEM validates whether that enforcement is actually working. Both rely on continuous monitoring of telemetry, assets and identities, and both push security from static to dynamic states.

Garbis adds that a zero-trust system treats CTEM as a source of near-real-time signals about the security posture of systems. Those signals feed directly into policy enforcement points, which use them to decide what access to permit for specific identities and resources.

The research from CDW paints a picture of two federal agencies working through the same fundamental problem: how to secure massive, complex environments without grinding operations to a halt. Neither has fully solved it, but both are finding that zero trust is less a destination than an ongoing adjustment process.