Zero Trust Without the Product Pitch

Zero trust is an operating discipline an organization practices over years, and the market sells it as a product tier an organization buys in a quarter. That gap explains a large share of stalled programs. A company funds microsegmentation or a zero trust network access gateway, deploys it into an environment whose actors and assets have never been fully enumerated, and finds several quarters later that it has purchased enforcement without a clear account of what is being enforced. The more useful question for a security team is which implicit trust the organization is removing, and in what order.

What the standard actually defines

Zero trust is a set of cybersecurity principles that removes implicit trust based on network location and evaluates every access request on its own terms. NIST Special Publication 800-207 sets out seven tenets, among them that all communication is secured regardless of network location, that access to individual resources is granted per session, that access is determined by dynamic policy including the observable state of identity and requesting asset, and that the enterprise continuously monitors the posture of the assets it owns and associates with. The architecture that follows is equally plain: a policy engine decides, a policy administrator executes, and a policy enforcement point enables, monitors, and terminates the connection. No vendor category appears in any of it, and each tenet describes something an organization does continuously rather than something it installs.

Reading the pillars as a scoreboard

The zero trust pillars are the five domains CISA uses to organize implementation in its Zero Trust Maturity Model version 2.0: Identity, Devices, Networks, Applications and Workloads, and Data, with three cross-cutting capabilities, Visibility and Analytics, Automation and Orchestration, and Governance, running through all five. Each is measured against four maturity stages, from Traditional through Initial and Advanced to Optimal. CISA states that each pillar can progress at its own pace and may move faster than others until cross-pillar coordination becomes necessary, and that design choice is more revealing than any critique of vendor marketing. An organization can sit at Advanced on Networks while remaining Traditional on Identity and Data, which is the exact profile a segmentation-first purchase tends to produce. The model measures gaps rather than spending.

The order that survives production

Sequencing matters because policy cannot be written against actors and assets that have never been inventoried. The migration path in SP 800-207 places identifying the actors on the enterprise, identifying the assets it owns, and evaluating the risks in its key processes ahead of formulating policy and identifying candidate solutions. Read as an operating order, that puts visibility first, then identity, then device posture, then segmentation, with governance running alongside from the start. Programs that invert the order fail in a recognizable pattern. Enforcement points go live, legitimate workflows break, exceptions accumulate to restore business function, and those exceptions quietly reconstitute the implicit trust the program was funded to remove.

The Department of Defense, which organizes its own program around seven pillars and a target level due by the end of FY2027, describes zero trust as "not a capability or device that may be bought."

Where NIST and CISA divide the work

NIST SP 800-207 and the CISA maturity model answer different questions, which is why teams so often ask which one to follow. NIST describes the architecture, covering the tenets, the logical components, the deployment variations and the trust algorithm that weighs each request. CISA describes progression, setting out pillars, stages and the criteria for moving between them, in a model aligned to OMB M-22-09. A serious program uses the first to design and the second to report. Treating either as a substitute for the other produces roadmaps that name maturity levels without ever naming the architecture underneath them.

Three questions that show where a program really stands

Maturity in zero trust is demonstrated by evidence rather than by architecture diagrams. Boards can test it with three questions. Can we enumerate the actors and assets in this environment, and how recently was that inventory verified? Which pillar are we honestly at Traditional on, measured against CISA's own criteria rather than our roadmap? What implicit trust does the next purchase remove, and what evidence will show that it was removed? A program that can answer all three is running an operating discipline. A program that answers with a product roadmap is running a procurement plan, and the difference will surface the first time someone tests it.


Sources

  1. National Institute of Standards and Technology, NIST Special Publication 800-207: Zero Trust Architecture (August 2020). https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf

  2. Cybersecurity and Infrastructure Security Agency, Zero Trust Maturity Model, Version 2.0 (April 2023). https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf

  3. Cybersecurity and Infrastructure Security Agency, Zero Trust Maturity Model (program page). https://www.cisa.gov/zero-trust-maturity-model

  4. U.S. Department of Defense, DoD Zero Trust Strategy (21 October 2022). https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-ZTStrategy.pdf


Disclaimer

This article is provided for general information only and does not constitute legal, regulatory or professional security advice. Zero trust implementation requirements vary by organization, sector and applicable federal guidance, and references to NIST, CISA and Department of Defense publications reflect those documents as published at the time of writing. Organizations should verify current guidance against the primary sources and seek qualified advice before making architectural or investment decisions.


Zero Trust

Questions boards and security teams ask

  • Zero trust architecture is an enterprise cybersecurity architecture built on zero trust principles, in which no implicit trust is granted to an account or asset based on its network location or ownership, and every access request is authenticated and authorized before a session is established. NIST SP 800-207 defines it as a plan encompassing component relationships, workflow planning and access policies, which means an organization adopts zero trust as a strategy first and derives its technology choices from that strategy afterward.

  • The zero trust pillars are the five domains in CISA's Zero Trust Maturity Model version 2.0: Identity, Devices, Networks, Applications and Workloads, and Data, supported by three cross-cutting capabilities called Visibility and Analytics, Automation and Orchestration, and Governance. Because CISA scores each pillar separately across four maturity stages, an organization should expect an uneven profile rather than a single overall grade, and the weakest pillar usually tells the more useful story.

  • Zero trust implementation starts with identifying the actors, assets and key business processes in the environment, because access policy cannot be written against resources that have not been inventoried. The migration path set out in NIST SP 800-207 places that discovery work ahead of formulating policy and selecting candidate solutions, which in practice means visibility first, then identity, then device posture, then segmentation, with governance running through all of it.

  • NIST SP 800-207 defines the architecture, including the seven tenets and the policy engine, policy administrator and policy enforcement point components, while CISA's Zero Trust Maturity Model defines progression across pillars and maturity stages in a model aligned to OMB M-22-09. Most organizations need both, using NIST to design the architecture and CISA to measure and report where each pillar currently sits.

  • Zero trust is a strategy and an operating discipline rather than a product, though products implement parts of it. The DoD Zero Trust Strategy states that zero trust may include certain products but is not a capability or device that may be bought, and the practical test for any purchase is whether it removes a specific instance of implicit trust that the organization can name and evidence.

Next
Next

Securing Payment Pages Under PCI