Skip to content

[REVIEW] zero-trust-assessment: add unmanaged device browser isolation gates #2743

@stmr

Description

@stmr

[REVIEW] zero-trust-assessment: add unmanaged device browser isolation gates

Skill Being Reviewed

Skill name: zero-trust-assessment
Skill path: skills/identity/zero-trust-assessment/

False Positive Analysis

Allowing unmanaged-device access can be acceptable when browser isolation disables download, clipboard, print, local storage persistence, and risky plugin access.

Coverage Gaps

The skill should verify unmanaged-device policy behavior. "Browser isolation enabled" is not enough without evidence of data movement controls and session cleanup.

Edge Cases

  • Screenshots or copy/paste bypass isolation.
  • Mobile browser behavior differs from desktop.
  • App opens direct file URLs outside isolated browser.

Remediation Quality

  • Add evidence fields: device state, app sensitivity, isolation mode, DLP controls, clipboard/download/print policy, and session cleanup.
  • Require negative tests for data export.
  • Flag unmanaged direct access to sensitive apps.

Comparison to Other Tools

CASB/ZTNA tools enforce isolation; assessment must verify effective user controls.

Overall Assessment

Add unmanaged-device isolation gates so BYOD access is constrained and testable.

Bounty Info

  • I have read and agree to the CONTRIBUTING.md bounty terms.
  • Preferred payment method: PayPal samik4184@gmail.com

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions