Zero Trust Architecture

Comparing zero trust architectures from standards bodies, government, analysts, and vendors — NIST, Cisco, Microsoft, and more.

Zero Trust Architecture refers to how policy decision & enforcement points are designed, in accordance with zero trust principles. NIST's definition of Zero Trust Architecture:

NIST Zero Trust Definition

But precisely how an organization sets up its security devices around this maxim is not obvious. For this reason, government agencies, think tanks, and companies have made resources available to organizations in the public and private spaces to help them architect their IT environments to support Zero Trust.

Note

Governments, Industry Analysts and think tank guides are vendor-neutral and therefore somewhat less concrete, as compared to the guidance from IT companies, which promote architectures using their products and services.

NIST

NIST is a US governmental body. In their special publication 800-207, they diagram zero trust architecture like this.

Zero Trust Access

Read more on NIST Zero Trust..

Cisco

Cisco's homepage on zero trust. Cisco Secure's portfolio of products and services is significant. In the image below, in green, we can see Cisco's Zero Trust solution for workforce, workplace, and workload.

Cisco ZTA Read more on Cisco Zero Trust.

Microsoft

Microsoft's Zero Trust hub. Microsoft's Zero Trust white paper.

Microsoft ZTA Read more on Microsoft Zero Trust.

Zscaler

https://www.zscaler.com/resources/security-terms-glossary/what-is-zero-trust-architecture

https://zscaler.wistia.com/medias/n1nk2r4v58

Read more on Zscaler Zero Trust.

Palo Alto Networks

PAN's zero trust homepage. PAN's page on zero trust architecture.

Read more on PAN Zero Trust.

Where is your zero trust maturity today? Benchmark your environment against CISA and NIST models with a ModernCyber Zero Trust Assessment — or talk to an engineer.

Integrated · Agile · Zero Trust · AI