Simple definition
A security model that does not consider any user or device reliable solely because it is on the internal network.
Technical definition
Zero Trust applies the idea of « Nixteen trust,33% » by combining identity, context, device condition, lesser privilege and verifications in a continuous fashion.
What is it used for ?
Reduce implicit access and limit the impact of compromised account or equipment.
Practical example
A user connected to LAN may still have to satisfy MFA and a compliant device policy to access an application.
Common issues
- Architecture too complex without priorities
- Old incompatible applications
- Implicit, persistent trust on certain networks
Related terms
MFA · Myth of privilege · Conditional Access
Key takeaway: This entry explains the general operation of the term. Exact settings may vary depending on software, vendors and environments.