Zero trust architecture

The architectural version of zero trust removes implicit trust based on network location and checks each request on its own merits.

Published reference architectures set out the components: a policy engine making decisions, enforcement points applying them, and signals about identity and device feeding both. It is a design pattern rather than a product, which is the main thing the market obscures.

Checked against the primary source.

More on Frameworks & standards