Zero Trust is a security paradigm that assumes no user, device, or network is inherently trusted. Access decisions rely on continuous verification, least privilege, and contextual signals. It is applied to protect distributed cloud environments, hybrid infrastructures, and modern identity-driven access scenarios.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Zero Trust is a security model that requires every access to be checked and continuously controlled regardless of network location.
Security analyst John Kindervag popularized the term Zero Trust at Forrester. The model arose as internal network boundaries stopped providing dependable protection; NIST later documented the architecture in SP 800-207.
Each request is evaluated using identity, device, context and authorization. Access applies only to the needed resource and time, and trust is continuously reassessed.
Network membership does not create automatic trust.
Every access is authenticated and authorized in context.
Segmentation, policies and monitoring limit damage.
Zero Trust structures protection for distributed systems, cloud services and mobile workforces.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.