Zscalerのブログ
Zscalerの最新ブログ情報を受信
The End of Legacy Data Classification Is a Zero Trust Opportunity for Federal Government
Across the Department of War, civilian agencies, and the Intelligence Community, security teams have spent years building data classification and permissions governance programs around on-premises tools. Those tools scanned file shares, monitored user activity, and helped auditors answer a basic question: who has access to what?
Now, legacy data classification vendors are retiring their on-premises products and shifting exclusively to cloud delivered models. For some organizations, that transition is straightforward. For federal teams operating in classified, air gapped, disconnected, or otherwise constrained environments, it creates a decision point.
Agencies have choices beyond a like-for-like replacement. They can replicate yesterday's static approach. They can reach for familiar fixes, such as bolting on another single purpose appliance or extending legacy VPN and perimeter access to reach new tools, which likely both adds cost and complexity and expands the attack surface. Or they can use the transition to strengthen continuous data visibility, access governance, and risk reduction as their Zero Trust and AI programs advance.
Federal guidance supports that broader approach. CISA’s June 2026 zero trust guidance describes decisions informed by identity, device posture, application context, and data sensitivity. The Federal Zero Trust Data Security Guide puts the data-security task plainly: "Practitioners should define their policies based on data sensitivity, identifying who can access the data, under what conditions, and what they can do with it.” In a June 2026 joint statement, the heads of the Five Eyes cybersecurity agencies likewise urged leaders to prioritize reducing their attack surface and review permissions regularly."
That modernization must account for wherever the mission runs: in the cloud, in hybrid environments, and in the classified, air gapped, and disconnected networks that much of the federal enterprise depends on.
Classification alone was never the whole answer
Even before end of life announcements, legacy data classification tools had structural limitations. Most operated on a static model: scan a repository, apply labels, generate a report. That approach answered where sensitive data lived at the time of the last scan, but could not keep pace with how data actually moves through an organization. Classification helps teams identify sensitive data. The broader task is to understand who and what can reach that data, whether access is appropriate, and how exposure changes as data and permissions change.
Data Security Posture Management (DSPM) reframes the problem. Instead of static classification alone, DSPM introduces data provenance, which maps exact data lineage and usage over time. It brings discovery and classification together with analysis of access and exposure. It connects data stores to the identities that access them, including human users, non-human identities, service accounts, third parties, and mission partners. It does this continuously, so the picture stays current as the environment changes.
For federal organizations, this is the difference between a compliance checkbox and an operational capability. It also matches the direction of the Pentagon’s cybersecurity policy. In March 2026 congressional testimony, Department of War CIO Kirsten Davies said the department will “emphasize automation and dynamic and continuous monitoring” and “drive risk reduction rather than burdensome paperwork”. For the data pillar, that means continuous posture assessment in place of periodic scans, and identity aware access governance in place of static permission reports.
Why Data Security Has to Become Continuous
The real challenge for agencies, therefore, is not simply how to replace a retiring classification tool. It is whether the replacement will support the way federal missions now operate.
Traditional categorization programs were built around labels, repositories, and periodic reviews. Those capabilities still matter, but they are no longer enough. Zero Trust requires agencies to understand data sensitivity in context: who is accessing the data, from what identity or workload, under what conditions, and whether that access remains appropriate over time.
That shift evolves the mission of data security. Categorization becomes the starting point, not the end state. Agencies need continuous visibility into sensitive data, identity-to-data relationships, excessive permissions, stale or redundant information, and policy violations that increase operational risk. They also need those capabilities to work inside the environments where federal data actually resides, including classified, disconnected, tactical, hybrid, and cloud-connected networks.
What Zscaler DSPM delivers
Zscaler DSPM helps agencies discover sensitive data, map identity to data access, and remediate exposure inside a customer controlled boundary. The approach follows four stages:
Discover. Connect to file stores, SaaS platforms, identity sources, and data repositories through agentless, API based, and service account connectors. Sensitive data stays within the operating boundary throughout.
Categorize. Apply deterministic rules, local machine learning, and optional customer controlled models to label sensitive data. Classification runs within the customer's environment, not in a third party cloud.
Graph. Map human and non human identities to data access, including privileged users, third party contractors, inactive accounts, service accounts, and identities without multi-factor authentication. This identity to data graph is the foundation for understanding who can reach what.
Remediate. Right size permissions, reduce stale or misplaced data, and produce the evidence auditors and governance teams need. The output is actionable: specific findings tied to specific data stores, with clear remediation paths and owner assignments.
Built for constrained environments
Zscaler DSPM is designed for environments where deployment flexibility is a mission requirement. That includes on-premises installations, VM and container based deployments, classified enclaves, and disconnected or tactical networks. Agencies operating in air gapped or limited connectivity environments do not need to route sensitive data through external cloud infrastructure to gain classification and access governance capabilities.
This deployment model directly addresses the friction federal teams encounter when their incumbent vendor's replacement requires connectivity and cloud models that do not fit the operational environment. Zscaler DSPM meets agencies where they operate, under the data boundary constraints, FedRAMP or Impact Level requirements, and RMF/ATO considerations that define federal IT.
The AI readiness imperative
There is a second, equally urgent reason to modernize data security posture now: AI adoption.
Agencies across the Department of War (DoW) and civilian government are under pressure to deploy AI, copilots, retrieval augmented generation (RAG) workflows, and agentic systems. Every one of those initiatives depends on access to internal data. Speaking at the 2026 Billington CyberSecurity Summit, acting Federal CISO Michael Duffy described the overlap directly: “The things that I need to advance data security for zero trust, and the things that we need to make data trustworthy and usable for AI are very much aligned. Sometimes even the same things.” Scaling AI safely depends on the organization’s ability to answer three questions:
Which data is sensitive, and where does it live?
Who and what can access that data today, including AI tools and automated workflows?
Are permissions appropriately scoped, or do broad legacy access rights create unacceptable exposure?
Zscaler DSPM provides the data foundation that makes AI adoption defensible. By identifying sensitive data, mapping access, and reducing excessive permissions before AI workflows touch mission data, agencies can move from blocking AI adoption to enabling it under governance.
Securing data is foundational Zero Trust
Data security does not exist in isolation. The findings from a DSPM deployment connect directly to broader Zero Trust architecture decisions: which users should have private application access, where data loss prevention controls need to be applied, how identity risk should influence access policy, and where AI guardrails belong.
Zscaler DSPM provides the data foundation that powers the rest of the Zscaler Zero Trust Exchange. Agencies can start with data discovery and access governance, prove value on a specific repository or mission data set, and expand into private access, data protection, identity risk scoring, and AI security as the program matures.
A practical next step
The retirement of legacy on-premises classification tools is already underway. For agencies with active compliance mandates, the priority is standing up a modern replacement that meets their deployment, security, and governance requirements before the control gap widens.
A practical starting point: a 30 to 45 day data risk assessment focused on one mission data enclave or repository family. The assessment delivers an executive readout covering sensitive data exposure, stale and redundant data, excessive permissions, user activity patterns, and AI access control implications. That readout becomes the basis for a broader deployment, grounded in measurable risk reduction and a clear path to operational value.
Ready to move forward? Contact the Zscaler Federal team to schedule a Data Security and AI Readiness Workshop.
このブログは役に立ちましたか?
免責事項:このブログは、Zscalerが情報提供のみを目的として作成したものであり、「現状のまま」提供されています。記載された内容の正確性、完全性、信頼性については一切保証されません。Zscalerは、ブログ内の情報の誤りや欠如、またはその情報に基づいて行われるいかなる行為に関して一切の責任を負いません。また、ブログ内でリンクされているサードパーティーのWebサイトおよびリソースは、利便性のみを目的として提供されており、その内容や運用についても一切の責任を負いません。すべての内容は予告なく変更される場合があります。このブログにアクセスすることで、これらの条件に同意し、情報の確認および使用は自己責任で行うことを理解したものとみなされます。



