Security

What is Zero Trust?

Definition

Zero Trust is a security model that requires strict identity verification and authorization for every request, regardless of network location, removing implicit trust from internal networks.

Zero Trust is a cybersecurity framework that eliminates the concept of trusted zones inside a network perimeter. It operates on the principle 'never trust, always verify'. Every user, device, and application must be authenticated, authorized, and continuously validated before accessing any resource. The model was formally defined by Forrester Research analyst John Kindervag in 2010 and has been widely adopted as network boundaries dissolved with cloud computing and remote work.

Under Zero Trust, all traffic is treated as untrusted. Access decisions are based on identity, device health, context, and policy rather than IP address or network segment. Microsegmentation isolates workloads, and least-privilege access limits lateral movement. Continuous monitoring and logging detect anomalies in real time. The National Institute of Standards and Technology (NIST) published SP 800-207 in 2020, which outlines seven core tenets, including that all data sources and computing services are considered resources, and all communication must be secured regardless of network location.

Zero Trust is not a single product but an architectural strategy. It often incorporates technologies such as multifactor authentication (MFA), identity and access management (IAM), endpoint detection and response (EDR), and software-defined perimeters (SDP). While Zero Trust is sometimes conflated with network security alone, it spans identity, devices, applications, data, and infrastructure. Adoption accelerated after the 2020 executive order on improving the nation's cybersecurity, making Zero Trust a de facto standard for modern enterprise security architecture.

Key facts

  • Eliminates implicit trust based on network location or IP address.
  • Requires continuous verification of identity, device, and context for every request.
  • Microsegmentation enforces least-privilege access between workloads.
  • NIST SP 800-207 (2020) provides the authoritative framework for Zero Trust architecture.
  • Not a product; an architectural strategy integrating MFA, IAM, and monitoring tools.

How it works in practice

A financial institution migrates its internal apps to the cloud. Instead of granting VPN access to the corporate network, it deploys a Zero Trust architecture: every employee authenticates via MFA, devices are checked for compliance, and access to each application is granted individually. An attacker who compromises a laptop cannot reach the database server; only the specific app endpoint is visible. Continuous session monitoring triggers reauthentication if unusual behavior appears.

Related terms

Identity and Access Management (IAM) Multifactor Authentication (MFA) Microsegmentation Least Privilege Access Software-Defined Perimeter (SDP) NIST SP 800-207

References

More in Security

2FA

Two-factor authentication (2FA) is a security method that requires a user to present two distinct types of evidence to verify their identity, typically a password and a time-based one-time code from an authenticator app or hardware key.

Bot Management

Bot management detects automated web traffic and distinguishes it from human users, using behavioral fingerprinting and other signals to block malicious bots while allowing benign ones.

Credential Stuffing

Credential stuffing is a cyberattack in which automated tools use username-password pairs leaked from one site to try logging into other sites, exploiting password reuse.

DDoS

A DDoS (Distributed Denial of Service) attack overwhelms a target server, service, or network with massive traffic from many compromised computers, making it unavailable to legitimate users.

DDoS Scrubbing

DDoS scrubbing diverts attack traffic to a specialized filtering facility that removes malicious packets and forwards only legitimate traffic to the target network.

Firewall

A network security device or software that monitors and controls incoming and outgoing traffic based on predetermined security rules, acting as a barrier between trusted and untrusted networks.

IDS

An Intrusion Detection System (IDS) monitors network traffic or host activity for signs of malicious behavior or policy violations and generates alerts for security personnel.

IPS

An Intrusion Prevention System (IPS) is a network security device that monitors traffic inline and actively blocks malicious packets before they reach their target.

OAuth 2.0

OAuth 2.0 is an authorization framework that allows a user to grant a third-party application limited access to their resources on another service without revealing their password.

OpenID Connect

OpenID Connect (OIDC) is an identity authentication layer built on OAuth 2.0 that provides a signed ID token containing verified user identity claims.

Who Is Online

In total there are 63 users online: 0 registered, 55 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369