<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<?xml-stylesheet type="text/xsl" href="../part2stratml.xsl"?><PerformancePlanOrReport><Name>About BeyondCorp</Name><Description>A new approach to enterprise security... BeyondCorp is Google's implementation of the zero trust security model that builds upon eight years of building zero trust networks at Google, combined with ideas and best practices from the community. By shifting access controls from the network perimeter to individual users and devices, BeyondCorp allows employees, contractors, and other users to work more securely from virtually any location without the need for a traditional VPN.</Description><OtherInformation>BeyondCorp began as an internal Google initiative to enable every employee to work from untrusted networks without the use of a VPN. BeyondCorp is used by most Googlers every day, to provide user- and device-based authentication and authorization for Google's core infrastructure.</OtherInformation><StrategicPlanCore><Organization><Name>Google</Name><Acronym>G</Acronym><Identifier>_84639496-9a4d-11ea-9529-f29c1783ea00</Identifier><Description/><Stakeholder StakeholderTypeType="Generic_Group"><Name>Extended Workforces</Name><Description>BeyondCorp for everyone -- BeyondCorp can now be enabled at virtually any organization with BeyondCorp Remote Access—a cloud solution that can help you rapidly deliver secure remote access to internal web apps through Google’s global network, allowing your employees and the extended workforce to access work apps from virtually any device, anywhere, without a traditional remote-access VPN.</Description></Stakeholder></Organization><Vision><Description>Rapid delivery of secure remote access to internal web apps.</Description><Identifier>_84639572-9a4d-11ea-9529-f29c1783ea00</Identifier></Vision><Mission><Description>To have every Google employee work successfully from untrusted networks without the use of a VPN.</Description><Identifier>_846395fe-9a4d-11ea-9529-f29c1783ea00</Identifier></Mission><Value><Name>Principles</Name><Description>BeyondCorp principles</Description></Value><Value><Name>Connection</Name><Description>Connecting from a particular network must not determine which services you can access</Description></Value><Value><Name>Knowledge</Name><Description>Access to services is granted based on what we know about you and your device</Description></Value><Value><Name>Authentication</Name><Description>All access to services must be authenticated, authorized, and encrypted</Description></Value><Value><Name>Authorization</Name><Description/></Value><Value><Name>Encryption</Name><Description/></Value><Goal><Name>Components</Name><Description>Define the high-level components of BeyondCorp</Description><Identifier>_84639680-9a4d-11ea-9529-f29c1783ea00</Identifier><SequenceIndicator/><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/><Objective><Name>Sign-On</Name><Description>Support single sign-on</Description><Identifier>_84639702-9a4d-11ea-9529-f29c1783ea00</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Proxy</Name><Description>Provide access proxy</Description><Identifier>_8463977a-9a4d-11ea-9529-f29c1783ea00</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Access</Name><Description>Provide an access control engine</Description><Identifier>_846397fc-9a4d-11ea-9529-f29c1783ea00</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Users</Name><Description>Maintain a user inventory</Description><Identifier>_8463987e-9a4d-11ea-9529-f29c1783ea00</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Devices</Name><Description>Maintain a device inventory</Description><Identifier>_84639900-9a4d-11ea-9529-f29c1783ea00</Identifier><SequenceIndicator>5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Security</Name><Description>Enforce security policy</Description><Identifier>_84639982-9a4d-11ea-9529-f29c1783ea00</Identifier><SequenceIndicator>6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Trust</Name><Description>Provide a trust repository</Description><Identifier>_84639a04-9a4d-11ea-9529-f29c1783ea00</Identifier><SequenceIndicator>7</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate>2011-12-31</StartDate><EndDate/><PublicationDate>2020-05-20</PublicationDate><Source>https://cloud.google.com/beyondcorp</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></PerformancePlanOrReport>
