Zero Trust Architecture (ZTA)
A security model that grants no implicit trust based on network location or asset ownership, instead authenticating and authorising every user, device and request before and during access to each resource.
Zero trust replaces the traditional perimeter model, in which anything inside the corporate network was trusted, with the assumption that an attacker may already be present on the network. NIST Special Publication 800-207 describes the core logical components: a policy engine decides whether a subject may access a resource, a policy administrator acts on that decision, and a policy enforcement point enables, monitors and terminates each connection. Decisions draw on identity, device health, behaviour and the sensitivity of the resource.
Organisations adopt zero trust as users, applications and data move beyond a single network to cloud services, remote working and partner connections. Typical building blocks include strong authentication such as multi-factor authentication, least-privilege access, micro-segmentation, encryption of traffic and continuous monitoring of activity. In manufacturing, the same principles are applied alongside OT-specific guidance such as the zones and conduits model of IEC 62443.
Zero trust is a strategy rather than a single product, and most organisations migrate gradually, starting with identity, remote access and their most valuable assets. Legacy systems that cannot support modern authentication need compensating controls such as gateways or segmentation. NIST SP 800-207 and the Zero Trust Maturity Model published by the US Cybersecurity and Infrastructure Security Agency (CISA) are widely used references for planning and measuring progress.
Key points
- No implicit trust is granted on the basis of network location or asset ownership.
- Each access request is authenticated and authorised before a session is granted.
- NIST SP 800-207 defines the reference architecture and its policy components.
- Adoption is incremental, usually starting with identity and critical assets.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Multi-Factor Authentication (MFA)Cybersecurity & Compliance
- Principle of Least PrivilegeCybersecurity & Compliance
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- Purdue ModelOT & Industrial Cybersecurity
- Security Information and Event Management (SIEM)Cybersecurity & Compliance
- Public Key Infrastructure (PKI)Cybersecurity & Compliance
Terms that refer to Zero Trust Architecture (ZTA)
- Broken Access ControlCybersecurity & Compliance
- Defence in DepthOT & Industrial Cybersecurity
- Deny-by-Default ControlOT & Industrial Cybersecurity
- Device Provisioning (Onboarding)Industrial IoT & Edge
- Hardware Root of TrustOT & Industrial Cybersecurity
- Identity and Access Management (IAM)Cloud & AI Infrastructure
- OAuth 2.0Cybersecurity & Compliance
- PasskeysCybersecurity & Compliance