Zero Trust Architecture offers a consistent approach to security by validating and continuously monitoring all access regardless of its source. This significantly reduces the risk of data breaches.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Zero Trust Architecture is a security model for distributed IT systems. Access is not considered trustworthy merely because it originates inside an internal network. Every request is evaluated using identity, device, target resource, and current context, and receives only the permissions it needs.
The model emerged in response to cloud services, mobile work, and distributed applications, where a fixed network perimeter no longer provides reliable protection. NIST SP 800-207 describes zero trust as an architectural approach for protecting resources in modern enterprise environments.
The resource, rather than the network segment, is the center of protection. A policy decision point evaluates each access request using available signals and rules. A policy enforcement point applies that decision by allowing, constraining, or denying access. Identities, devices, and sessions are assessed continuously. Least privilege and segmentation also limit the potential impact of a compromised account or system.
Protection decisions concern specific data, services, and systems rather than a supposedly trusted network zone.
Identity, device posture, and context are evaluated repeatedly during access; one-time trust is insufficient.
Access receives only the permissions and duration required for the specific task.
A decision component evaluates signals and rules, while an enforcement component technically allows or denies access.
Zero Trust Architecture is especially relevant to cloud and hybrid environments, remote work, sensitive services, and limiting lateral movement after a breach. Adoption requires dependable identities, an inventory of protected resources, telemetry, and clearly owned access policies; it is not a single product that can be installed in isolation.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.