Zero Trust
Zero Trust is an IT security concept in which users, devices and applications are not trusted solely because of their location within a network. Every request to access systems, data and other resources is evaluated and authorised according to defined security policies. Identity, device security posture, access permissions and other contextual information can form part of this assessment. Core principles include strong authentication, least-privilege access and continuous monitoring of access activity. Technologies such as multi-factor authentication, Identity and Access Management, network segmentation and Endpoint Security can form part of a Zero Trust architecture. The objective is to restrict unauthorised access and limit the ability of attackers to move through an IT infrastructure. Zero Trust is not a single product, but a comprehensive security model for modern enterprise networks, cloud environments and hybrid IT infrastructures.