Standards

What Zero Trust actually means, according to the bodies that defined it

Security, at the edge

Gartner hails a SASE future. Forrester calls it Zero-Trust Edge.

Secure Service Access Edge (SASE) or Zero-Trust Edge (ZTE) is the concept of combining network security functions with WAN capabilities in such a way so as to align with Zero Trust principles. Implementations are primarily delivered as a Service and policy decisions are based on the identity of connecting entities, real time context and security posture. While SASE points to a larger amalgamation of existing tooling, Zero Trust Network Access (ZTNA) is a central component of the architecture.

Andrew Lerner, Gartner (2019) & David Holmes, Forrester (2021)
Gartner hails a SASE future. Forrester calls it Zero-Trust Edge.

The Seven Tenets of Zero Trust

NIST Special Publication 800-207

Zero Trust, defined: The United States National Institute of Standards and Technology (NIST) defines Zero Trust and a Zero Trust Architecture in terms of seven basic tenets. These tenets are the ideal goal, not all tenets need be fully implemented in their purest form for a given strategy. The British National Cyber Security Centre (NCSC) has also published guidance in which they define eight principles to help organizations adopt Zero Trust.

1. Everything is a Resource

3. Session-based access

5. Monitor security posture

7. Measure and Improve

NIST Special Publication 800-207

2. Secure all communications

4. Policies must be dynamic

6. Authenticate before connect

NIST Special Publication 800-207

1. Everything is a Resource

All data sources and computing services are considered resources

2. Secure all communications

All communication is secured regardless of network location

3. Session-based access

Access to individual enterprise resources is granted on a per-session basis

4. Policies must be dynamic

Access to resources is determined by dynamic policy and real-time security posture

5. Monitor security posture

No asset is inherently trusted

6. Authenticate before connect

Resource authentication and authorization is dynamic and strictly enforced before access is granted

7. Measure and Improve

Collect as much data as possible, monitor and measure the integrity and security posture of all assets and use it to improve security posture

Zero Trust Network Access

Approach meets architecture

Zero Trust Network Access

Zero Trust Network Access, or ZTNA is a Zero Trust approach to private networking which Gartner define, as "a product or service that creates an identity- and context-based, logical access boundary around an application or set of applications. The applications are hidden from discovery, and access is restricted via a trust broker to a set of named entities."

Put simply, these principles are:

  • Applications are hidden from discovery, no public visibility
  • Access is restricted via a trust broker
  • The trust broker verifies the identity, context and policy
  • Lateral movement in the network is prohibited
  • There is a reduced surface area available for attack