Start with Identity
← Glossary
Concept

Zero Trust

A security model where trust is never assumed based on network location and is continuously re-evaluated. Each access decision considers identity, device posture, and context. Codified in NIST SP 800-207. Distinct from ZTNA, which is the access control product category.

Zero trust is a set of design principles, not a product, and the identity parts are the ones that actually get implemented: strong authentication, device posture, per-application authorization, and continuous re-evaluation instead of a one-time gate at the perimeter. NIST SP 800-207 is the reference worth reading, mostly because it is vendor-neutral enough to argue with.

See also: what is zero trust, conditional access, ZTNA, zero trust vendors

Last reviewed By SWI Community TeamSuggest a correctionHow we research