THREAT BRIEFING · 13.08.2026 DEENFRES

Security Glossary

What Is Zero Trust? Definition, Principles, and Components

By Alec Chizhik · July 7, 2026 · 5 min read

What is Zero Trust? Zero Trust is a security model that does not implicitly trust any user, device, or network location. Every access request is individually authenticated, authorized, and inspected, following the principle of never trust, always verify. Zero Trust is a security architecture model and not a product category. The central reference is the NIST publication SP 800-207.

Key Takeaways

  • Principle: No implicit trust. Every request is verified, regardless of whether it comes from the corporate network or from outside.
  • Building blocks: Strong identities, verified device status, microsegmentation, minimum permissions, and ongoing verification.
  • Perspective: Zero Trust is an architecture. Individual products implement parts of it; no purchase replaces architectural decisions.

What Zero Trust Actually Means

The classic security model draws a boundary around the corporate network and trusts everything that moves inside it. Exactly this implicit trust is exploited by every attacker who manages to get inside the perimeter. Zero Trust breaks with this assumption: Every access request is verified without implicit trust, based on identity, device, and context.

SP 800-207

The NIST reference architecture for Zero Trust, published in August 2020

Source: NIST

The NIST reference formulates clear principles for this. All data sources and services are considered resources. Every communication is secured independently of network location. Access is granted per session, never permanently. Decisions are made by a dynamic policy comprising multiple attributes, such as identity, device status, and behavior. The state of all systems is continuously monitored.

The Real Building Blocks

In practice, it all begins with identity. A centralized identity and access management system that employs continuous multi‑factor authentication (MFA) lays the foundation, because without trustworthy identities no policy can take hold. Right alongside that comes device posture: patch level, endpoint protection and compliance flow into every access decision.

Then there’s micro‑segmentation, which isolates applications and network zones with fine‑grained precision. Least Privilege adds the finishing touch by granting only the minimum rights per session and resource. The fifth building block is continuous verification: identity and context are checked throughout the entire session, not just at login. These five elements form the core of any Zero‑Trust architecture.

What companies need to check now

The process starts with an inventory. If you don’t know which identities, devices and applications exist, you can’t enforce access controls. Next come the levers with the biggest impact: securing identities and protecting the most critical resources first.

CHECK NOW

  • Create an inventory of all identities, devices, applications and data resources
  • Implement centralized identity management with continuous multi‑factor authentication (MFA) for all accesses
  • Establish device posture checks before and during access
  • Isolate critical applications and data flows via microsegmentation
  • Build logging and a policy engine for session‑ and attribute‑based decisions

Distinguishing Related Concepts

The key difference concerns the VPN. A VPN extends the perimeter: once connected, users often gain broad access to entire network segments. Zero Trust flips the logic and grants access only to the specific resource, only for the current session and only after verification. ZTNA solutions implement exactly this application access, they are a building block and not yet a full Zero-Trust architecture.

Similarly clear is the distinction from product claims. No single tool creates Zero Trust, even though many vendors’ marketing suggests otherwise. The architecture stems from decisions about identities, rights, segments and policies. Tools follow these decisions.

Frequently Asked Questions

Each question is locked. Tapping unlocks the answer.

Is Zero Trust a product?

No. Zero Trust is an architecture model. Identity Provider, endpoint protection, microsegmentation and ZTNA assist in implementation, but product decisions are not left to a product.

Does Zero Trust replace VPN?

Not necessarily and not immediately. The goal is to phase out broad network access and replace it with verified connections to individual resources. A VPN can continue in some areas on a transitional basis.

What is ZTNA?

Zero Trust Network Access is a concrete implementation approach for application access. Access is granted only after verification of identity, device and context, without the client needing to be on the same network.

Where to start?

Start with inventory and identities: centralized IAM, full MFA and protection of privileged accounts. Then move on to the most critical applications. Full migration proceeds gradually over years.

What does NIST say about Zero Trust?

NIST describes in SP 800-207 the reference architecture with its principles: no implicit trust, session-based access, dynamic policies and continuous monitoring.

Editor’s Picks

Editor’s PickMicrosegmentation: Why Network Segmentation Alone Is No Longer EnoughEditor’s PickPasskeys in the Enterprise: The End of the Password

More from the MBF Media Network

cloudmagazinBanning shadow AI is the most expensive reflex in IT securityMyBusinessFutureTool Hygiene in Small and Medium-Sized Enterprises: 5 Hard LessonsDigital ChiefsManaged Security Services: CISO Does Not Bear Sole Liability

Further reading

A magazine by Evernine Media GmbH