Zero Trust Architecture
Zero Trust Architecture is a security model in which no user, device, network or service is automatically considered trustworthy. Every access is checked in context, limited to the necessary minimum and continuously monitored. The architectural approach follows the principle of “never trust, always verify” and is intended to prevent attackers from moving unhindered through an IT environment after a successful intrusion.
A zero trust architecture combines identity verification, strong authentication, device assessment, segmentation, policies, telemetry and continuous risk analysis. Instead of aligning security primarily with the network perimeter, individual accesses to applications, data and services are controlled. This is particularly relevant for cloud environments, remote work, hybrid infrastructures and distributed supply chains. A suitable solution framework is provided by Zero Trust within IT security.
The term overlaps with Zero Trust Security, but focuses more strongly on the structure, components and interaction of the security architecture. Important prerequisites are clear identities, traceable access policies and an up-to-date picture of the organization's own security situation. Zero trust architecture is therefore closely related to Identity Security and a resilient Security Posture.
See also: Cloud Security and Cyber Risk Management.