Modern businesses face a wide variety of external and internal threats that require a complete approach to security. Organizations can improve their security posture by implementing the zero trust model to closely control how users gain access to sensitive data and critical assets.

Zero trust acknowledges that internal threats exist and must be mitigated to protect the business. Zero trust eliminates implicit trust, treats all access requests as potential security breaches, and takes necessary steps to protect the IT environment.

The entire company must be involved in zero-trust adoption. Executive buy-in and strong cross-team support are essential for successful zero trust transformation. Zero trust offers a more effective security strategy than traditional security models.

Zero Trust Security Model and Principles

The zero trust model is built on the precept of “Never Trust, Always Verify.” No implicit trust is granted based on network location or previous activity. The foundation of the zero trust architecture comprises the following core principles.

  • Explicit verification: Activity must be authenticated and authorized with strict access controls based on more than network position. All available signals, such as identity, device health, location, and behavior, are considered regardless of whether the request comes from within or outside of the corporate network.
  • Least privilege access: Users, systems, and devices are granted only the minimum level of access needed to perform a given task or job role.
  • Assume a breach: The zero trust architecture is designed to address attackers that have already breached the network, unlike traditional security models that focus on keeping intruders out.
  • Micro-segmentation: Network security is strengthened by segmenting the network into small zones. The purpose of this segmentation is to restrict broad access to the entire IT environment if one system is compromised.
  • Continuous verification: Trust must be reevaluated for every session and user request. All access requests must pass strong identity verification before permission is granted to proceed, even if previously authenticated.

The main objective of a company’s zero trust efforts is to ensure all access requests are verified at every step through the environment. These core principles support the strong system and data security required to protect business-critical resources.

Define the Attack Surface

Organizations must define their attack surface and build a security framework that protects their Data, Applications, Assets, and Services (DAAS). Teams must inventory and identify critical assets and sensitive data to accurately define the attack surface that needs to be defended. All external dependencies that interact with these assets and expand the attack surface must be included in this inventory.

Businesses can prioritize the identified assets when developing their zero trust strategy. They can focus on protecting critical assets first, then move on to the remaining infrastructure elements to improve their security posture across the organization while maintaining operations.

Map Network Traffic and Transaction Flows

Access management for users already inside the corporate network is an aspect of the zero trust security model. Teams should map all network traffic between users, applications, and data stores. The objective is to identify the most effective policy enforcement points for all critical data flows that protect resources while facilitating smooth business operations.

Zero trust security extends to network access attempts by remote workers and third parties trying to connect with on-premises or cloud resources. Companies should record and review connection patterns to determine whether security controls should be modified to protect business-critical systems and data better.

Architect the Trust Network

Security teams must design the architecture to protect the defined attack surface. They should use a methodical approach when developing the zero trust architecture, addressing the following characteristics.

  • The architecture must be designed around the defined attack surface. The primary goal of zero trust is to protect these and sensitive infrastructure components by restricting broad network access.
  • Teams should implement microsegmentation controls to ensure that access to a specific system does not allow lateral movement through the entire network to other critical resources. All access attempts must be verified to align with zero trust principles.
  • Businesses must select the locations where policy decisions on user identity and access requests should be made. Some users may be entirely prohibited from accessing certain network segments, while others will have limited permissions within those segments.
  • Policy decision points should be tightly coupled with policy enforcement points. Strict access controls should prevent unauthorized and unauthenticated users from accessing network segments or specific resources.

Implement Zero Trust Identity and Access Management

The key to the zero trust model is a reliable, centralized Identity and Access Management (IAM) platform that enforces multi-factor authentication (MFA) for all access requests. Strong identity verification is mandatory to support a zero trust approach.

Users can only be granted access to a subset of the IT environment. Organizations must develop and implement role-based access controls (RBACs) for all users, aligned with their job functions. Attribute-based policies should be defined to control contextual access decisions.

Admin accounts require special consideration when developing IAM policies. These accounts provide privileged access that must be tightly controlled and restricted to specific systems and resources. Admin privileges should always be provided on a limited basis to minimize insider threats.

Define Access Policies

Organizations can use the Kipling Method to build explicit, auditable, and secure access policies. The method defines the following criteria for every access policy based on six related questions. After each question is answered, the access request can be allowed to continue or terminated based on policy definitions.

  • Who: Which user or device is requesting access?
  • What: What application or resources are they attempting to access?
  • When: When is the entity permitted to use the resource?
  • Where: Where is the protected resource located, and where does the access request originate?
  • Why: Why is access being requested?
  • How: How will access be granted?

Every job role or service should be granted least-privilege access for a given system or resources. Decision-makers should periodically review these privileges and make the necessary modifications to address changes in the environment or role.

Secure Zero Trust Network Access

Zero Trust Network Access (ZTNA) enforces per-application and identity-verified access to IT resources. A ZTNA approach replaces the broad access enabled by traditional virtual private network (VPN) solutions with conditional access tied to user identity and device health and status.

A VPN typically enables users to access multiple internal systems once they are connected and verified. ZTNA’s application-level access connects a user only to the specific application they are authorized to use. The zero trust network approach reduces the blast radius if threat actors compromise credentials.

Device Trust, IoT Devices, and Endpoint Security

Zero trust network access controls must be designed to ensure secure access for users and devices. Modern businesses often deploy a range of automated IoT devices and endpoint solutions to support remote work. Teams should implement policies to verify device health before granting access. Device health checks are essential for identifying outdated firmware or patching vulnerabilities that threat actors can exploit.

One method of preventing IoT devices from accessing unauthorized resources is to limit access to specific dedicated network segments. This type of control involves planning to ensure IoT-connected applications live on an appropriate segment. All IoT access attempts to other segments should be refused.

Companies that engage managed service providers such as Atlantic.Net should expect them to provide complete edge security aligned with their zero-trust access policies.

Continuous Monitoring and Network Traffic Analysis

Companies must implement a continuous monitoring solution to support a zero trust security posture. Teams should collect identity and network activity telemetry in real time and be prepared to address incidents that may indicate threats or malicious activity. Security teams should implement advanced anomaly detection solutions leveraging threat intelligence and behavioral analysis.

When potential incidents are detected, automated alerts should be generated to trigger recovery and mitigation playbooks. The immediate goal is to reduce the business impacts of an unauthorized incursion by locking down the rogue user or device. All monitoring logs should be retained and archived for use in forensic investigations and to provide audit evidence.

Automate Policy Enforcement

Companies should deploy a policy engine to automate decisions and enforcement. Zero-trust security violations must be addressed in real time to protect the IT environment fully. Teams can evaluate unauthorized access attempts that were denied after the fact to determine if policies should be modified.

Organizations should define remediation workflows for non-compliant devices that fail health checks and result in denied access attempts. These devices should be serviced promptly to address their issues. Teams should strongly consider implementing policy-as-code to achieve more consistent deployments that comply with governance and compliance requirements.

Governance, Compliance, and Attack Surface Reduction

Organizations must exercise effective governance to avoid control drift, which can undermine the viability of zero trust. Governance efforts should incorporate the following elements.

  • Businesses should establish ownership and accountability by designating a zero-trust program owner and forming a cross-functional governance committee to make decisions about access policies and exceptions. The committee should formally document access policy standards and processes for handling exceptions.
  • Companies must support identity lifecycle governance that enforces zero-trust policies across an entity’s changing roles and revokes all access immediately when access is no longer needed. Access policies should be periodically reviewed and recertified to ensure they still align with business and security objectives.
  • Decision-makers should continuously review and tune zero trust policies. Excessive privileged access should be trimmed to eliminate the risk if credentials are compromised. Teams should use metric-driven tuning to make changes based on real-world events.

Companies must implement zero trust to support any applicable compliance frameworks such as HIPAA or PCI DSS. Access controls for sensitive and regulated data should align with compliance standards. Teams must document policies and retain logs to provide evidence for compliance audits.

Businesses should consider attack surface reduction to be an ongoing process. Efforts to reduce entry points for threat actors should be security-focused. Teams should schedule attack surface reduction exercises and use the results to inform infrastructure changes that support a zero-trust architecture.

Pilot, Rollout, And Iterative Expansion

Companies should begin their zero trust journey by selecting a high-impact pilot case to validate controls and processes. Teams can collect and evaluate key KPIs to gauge the impact of zero trust principles on user access to sensitive data and on operational metrics.

Once the organization is satisfied with the details of its zero trust strategy, security controls can be scaled across additional applications and cloud resources. Ideally, replicating the strict access controls across all critical assets can be done with minimal impact on business operations.

Zero Trust Checklist

Teams can consult the following checklist of the major components of zero trust.

  1. Identify the critical DAAS that must be protected and the attack surface that provides threat actors access to these resources.
  2. Inventory all users, devices, and applications to determine how they fit into the security and grant them least-privilege access to authorized assets.
  3. Deploy strong authentication methods including MFA and passwordless solutions when possible.
  4. Enforce infrastructure microsegmentation and device trust policies.
  5. Implement continuous monitoring and alerting solutions to identify and address threats in real time.
  6. Review policies and logs regularly to fine-tune access controls and address identified vulnerabilities.

Operationalize Maturity, Metrics, and Next Steps

Organizations that implement zero trust typically proceed through the following stages as the process matures.

  • Stage 0 -Traditional: Perimeter-based security via VPNs that support implicit trust once inside the network.
  • Stage 1 – Initial: Pilot program that implements ZTNA and MFA on select critical applications.
  • Stage 2 – Developing: ZTNA protects most applications, and companies introduce policy-as-code and define identity lifecycle processes.
  • Stage 3 – Defined: All applications are covered by ZTNA with minimal VPN usage and standardized policy-as-code deployment.
  • Stage 4 – Optimized: Characteristics include continuous verification, automated policy tuning, and adaptive risk-based access.

Teams commonly measure many KPIs to evaluate the effectiveness of their zero trust environment, including:

  • The percentage of users subject to MFA;
  • The percentage of applications migrated to ZTNA;
  • Mean time to detect (MTTD) anomalous behavior;
  • Mean time to respond (MTTR) to incidents;
  • Time to revoke access when offboarding employees;
  • Number of stale access grants revoked upon review.

Companies should schedule quarterly reviews of the zero trust policy’s scope and controls. The review provides an opportunity to refine controls to better protect sensitive resources. Businesses in the early stages of zero trust adoption should plan to cover all remaining assets and services and reach the phase as soon as possible.