Skip to content
Paul Marinos
Menu

Zero Trust

NIST SP 800-207 as it is actually written — per-request decisions at policy enforcement points, identity as the perimeter, microsegmentation, the CISA maturity gradient, and why buying it isn't doing it.

Strip the vendor language and NIST SP 800-207 says one thing: network location is not evidence of trustworthiness. Every access request gets authenticated, authorized and evaluated against current context — regardless of where it comes from — and the authorization holds for that request, not for the session, the subnet, or the badge that got someone into the building. Everything else in the model is machinery for making that one sentence true at scale.

  • Policy Decision Point and Policy Enforcement Point: every request path routes through an enforcement point that asks a decision point: should this be allowed, right now, given this identity, this device, this resource, this context? The words doing the work are “right now” — the decision is per-request and re-evaluated as context changes, which is what separates the architecture from a login page with extra steps.
  • Identity as the perimeter: with no trusted network, the entire authorization burden moves into identity and device posture. In practice that makes Conditional Access and its equivalents the real PDP of most estates — the place where “user + device + location + risk” becomes an allow, a step-up, or a deny.
  • Microsegmentation: the network half of the same principle: if no zone is trusted, no flow is implicit, and east-west reachability becomes something you grant rather than something that exists. Containment stops being an incident-time activity and becomes a property of the design.
  • Signals feeding the decision: device health, patch level, credential strength, behavioral risk — the decision point is only as good as its inputs, which is why zero trust programs quietly become telemetry programs.

The CISA Zero Trust Maturity Model is useful precisely because it refuses the binary. It grades five pillars — identity, devices, networks, applications, data — from traditional through optimal, and its honest implication is that every real organization is mid-gradient somewhere. The model turns “are we zero trust?” (unanswerable, and usually answered with a purchase order) into “which pillar is furthest behind and what moves it one stage?” — a question with a budget line attached.

Sequencing follows from where the leverage is. Identity signals and per-request policy come first because they upgrade every other pillar’s decisions; device posture second, because it is the input identity decisions most often lack; network segmentation runs in parallel as the long-lead item; data-level policy is usually last because it depends on classification actually existing.

  • As a purchase: ZTNA replacing the VPN is a fine project and is one pillar at one stage. Declaring victory there leaves lateral movement, standing privilege and implicit service-to-service trust exactly where they were.
  • As a rebranding: the same network, the same standing access, a new dashboard. The test is behavioral: did any request that used to succeed on location alone start failing? If nothing broke, nothing changed.
  • As a human-only model: the framework’s language assumes subjects that authenticate interactively. The non-human majority of the directory — and autonomous agents after them — stretch its assumptions hardest, because “verify at request time” presumes the requester’s identity and intent are stable things a policy can evaluate.

A credible mid-gradient program is concrete in ways a slide deck never is: phishing-resistant MFA (FIDO2, passkeys) enforced before anything else, because every later decision leans on the identity signal; device compliance feeding Conditional Access, with admin access gated on it first; ZTNA replacing the VPN application by application, starting with what contractors and third parties touch, since those users never belonged on the network at all. New environments get built east-west default-deny from day one while the legacy estate is segmented opportunistically — retrofitting is the expensive direction. And progress has an instrument: policies run in report-only mode before enforcement, so “what would fail under the new rule” is a report the program reads weekly, and the behavioral test — requests that once succeeded on location alone now failing — is measured rather than asserted.

This is one leg of the three-framework comparison. Its enforcement reality is Conditional Access on the identity side and segmentation architecture on the network side; its telemetry appetite is fed by the same sources detection engineering ranks richest. Where its assumptions run out — the platform that must itself be trusted, the agent whose intent isn’t evaluable at request time — is where Zero Knowledge Trust picks up the argument.

Graph View

Last updated:

Spotted an error on this page? Report it.