// THREAT DETECTION AND DATA PRIVACY TERM

Zero Trust

Zero Trust is a security model that assumes no user, device, or application, whether inside or outside an organization's network, should be automatically trusted. Instead, every access attempt is continuously verified and authorized before granting minimal necessary access.

Zero Trust — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

Zero Trust is a cybersecurity architecture and strategy that mandates explicit verification for every access request, operating on the principle of 'never trust, always verify' regardless of network location, leveraging identity, device posture, and least privilege access controls to continuously authorize and secure digital assets and resources via micro-segmentation.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • Zero Trust Architecture (ZTA)
  • Never Trust Always Verify
  • Perimeterless Security
  • Micro-segmentation Security
  • Least Privilege Security

USAGE NOTE

It is widely adopted as a foundational cybersecurity framework to mitigate insider threats and respond to perimeter breaches, though comprehensive implementation can be complex.

DEVELOPERS

Organizations developing technology related to Zero Trust.

  • Zscaler

    Offers a cloud-native Zero Trust Exchange platform that securely connects users and devices to applications, regardless of location, eliminating the need for traditional VPNs.

  • Palo Alto Networks

    Provides a comprehensive portfolio of Zero Trust Network Access (ZTNA) and Secure Access Service Edge (SASE) solutions, including next-generation firewalls and cloud security offerings.

  • Microsoft

    Implements Zero Trust principles across its extensive product suite, including Azure Active Directory for identity and access management, Microsoft Defender for endpoint security, and Microsoft Sentinel for SIEM.

  • Google (Google Cloud)

    Offers BeyondCorp Enterprise, a Zero Trust access platform that enables secure access to applications and resources from any device, anywhere, without a traditional VPN.

  • Okta

    Specializes in identity and access management (IAM) solutions, providing foundational components for Zero Trust architectures by ensuring secure user authentication and authorization.

  • Cisco

    Delivers a comprehensive Zero Trust strategy with solutions spanning network, endpoint, and application security, including Duo Security for MFA and Secure Access for ZTNA.

  • CrowdStrike

    Provides a cloud-native platform for endpoint protection, identity protection, and threat intelligence, essential for continuous verification and least privilege access in a Zero Trust model.

  • Fortinet

    Offers a Security Fabric platform that integrates various security solutions, including Zero Trust Network Access (ZTNA) and Secure SD-WAN, to enforce granular access control and continuous verification.

RELATED TERMS IN DEFENSE & ARCHITECTURE