Zero Trust

A security approach that continually evaluates access based on identity, device, context, and policy rather than assuming users or systems are trustworthy because of their network location.

Cloud & Systems

In plain English

Zero trust replaces the idea that everything inside a company network should automatically be trusted. Access is granted more deliberately, with users, devices, applications, and requests evaluated according to policy.

Example

An employee connecting from a managed laptop may still need strong authentication and authorization checks before opening a sensitive finance application, even while connected to the corporate network.

Sources

  1. CISA: Zero Trust Maturity Model