Zero Trust Is Not a Product: What NIST Actually Means by the Term
Few phrases in cybersecurity marketing have traveled further from their origin than “zero trust.” Vendors attach it to firewalls, identity platforms, network segmentation tools, and cloud access brokers, often with little connection to what the term was built to describe. The National Institute of Standards and Technology published the definitive account in August 2020, Special Publication 800-207, and it describes an architecture, not a product line.23
The core idea is a genuine departure from how network security worked for the previous two decades. Traditional security assumed that a user or device inside the corporate perimeter, connected to the office network, sitting behind the firewall, could be trusted more than one outside it. Zero trust architecture removes that assumption entirely. NIST's own language is precise on this point: an attacker is assumed to be present in the environment already, and an enterprise-owned network is treated as no more trustworthy than any other.24 Every request for access to every resource gets evaluated on its own terms, using identity, device posture, and context, regardless of where the request originates.
NIST organizes this around seven tenets. Among them: every data source and computing service counts as a resource requiring protection, all communication is secured regardless of network location, and access to individual resources is granted per session rather than persistently.25 None of these tenets specify a vendor, a product category, or a purchase. They specify design principles an organization can implement with tools it may already own, such as multifactor authentication, least-privilege access controls, and network segmentation, deployed according to a different underlying logic than before.
This distinction carries practical consequences. An organization that purchases a product marketed as “zero trust” without changing how access decisions get made has bought a name, not an architecture. A more useful question than “do we have zero trust” is a narrower one: can someone explain, for any given system, why a specific user has access to it, and would that access survive a review conducted today rather than one conducted at onboarding eighteen months ago?
Buzzwords earn their reputation honestly. They describe something real, get adopted as a sales term faster than the underlying practice can spread, and end up meaning everything and nothing at once. Zero trust is a genuine architectural principle with a specific federal definition behind it. Whether an organization has actually implemented it is a separate question from whether someone on a sales call used the phrase.
#CyberSecurity #ZeroTrust #NIST #InfoSec #GarlickGroup
23. National Institute of Standards and Technology, “Zero Trust Architecture: NIST Publishes SP 800-207,” August 2020, https://www.nist.gov/news-events/news/2020/08/zero-trust-architecture-nist-publishes-sp-800-207.
24. Scott Rose et al., Zero Trust Architecture, NIST Special Publication 800-207 (Gaithersburg, MD: National Institute of Standards and Technology, August 2020), https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf.
25. “What Is NIST SP 800-207? Zero Trust Architecture Framework,” Palo Alto Networks, https://www.paloaltonetworks.com/cyberpedia/what-is-nist-sp-800-207.
No comments:
Post a Comment