Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The 8 Design Principles Of A Zero Trust Network
Articles

The 8 Design Principles Of A Zero Trust Network

Matthew MargettsBy Matthew MargettsMay 24, 2022Updated:May 24, 20225 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The connected world is a changed world, and enterprises can no longer assume that they have full control over closed networks. Further accelerating the new normal is the COVID-19 pandemic, which shifted a large proportion of the workforce to remote working and forced businesses to increase their use of cloud platforms to support a variety of devices and networks. Unfortunately, criminals take advantage of this upheaval and attempt to increase network infiltrations for nefarious gains.

The truth is that legacy security solutions cannot support a zero trust network. In the legacy model, security measures are reliant on a closed perimeter security model that assumes that all users and applications are coming from the same network location and entry points. This approach is no longer sufficient, which is why zero trust security is becoming the preferred network security architecture.

What is zero trust security?

Zero trust architecture is an approach to IT system design where inherent trust in the network is removed. The network is assumed to be hostile, and each request is verified based on an access policy. Regardless of the device, network and user activity, zero trust architecture is built on access management checks at every level.

The National Cyber Security Centre (NCSC) says: “In a zero trust architecture, inherent trust is removed from the network. Just because you’re connected to a network doesn’t mean you should be able to access everything on that network. This is commonly seen in breaches; an attacker gains a foothold in a network and is able to move laterally because everything on the network is trusted. In a zero trust architecture, the network is treated as hostile.”

The key concepts of zero trust

  • The network is hostile and should be treated as compromised
  • Inherent trust is removed from the network
  • Every request to access data or a service should be authenticated and authorised against an access policy
  • Gain confidence dynamically by continuously evaluating the trustworthiness of connections

The 8 design principles of a zero trust network

The National Cyber Security Centre has introduced eight zero trust architecture design principles that are paving the way for future networks for the government. These eight principles are intended to help the public sector and large organisations to implement a zero trust network architecture in an enterprise environment.

1. Know your architecture, including users, devices, services and data

2. Know your user, service and device identities

3. Assess user behaviour, service and device health

4. Use policies to authorise requests

5. Authenticate and authorise everywhere

6. Focus your monitoring on users, devices and services

7. Don’t trust any network, including your own

8. Choose services that have been designed for zero trust

Let’s take a closer look at the eight principles’ objectives:

1. Know your architecture, including users, devices, services and data

To get the benefits from zero trust, you need to have a clear understanding about each component of your architecture so that you can identify:

  • Where your key resources are
  • The main risks to your architecture
  • How to avoid integrating legacy services that do not support zero trust

2.  Know your user, service and device identities

An identity can represent a:

  • User (human)
  • Service (Software Process)
  • Device

Each identity should be uniquely identifiable in a zero trust architecture. This is the most important factor in deciding whether or not something or someone should be allowed access to data or services.

3. Assess your user behaviour, devices and services health

The most important indicators when looking to establish confidence in the security of your systems are:

  • User behaviour
  • Service health
  • Device health

Zero trust policy engines need to be able to measure user behaviour, device health and service health.

4. Use policies to authorise requests

The power of a zero trust architecture lies in the defined access policies. Each request for services or data should be authorised against a specific security policy. These policies also help to facilitate safer sharing of data or services with partner organisations or guest users.

The key characteristics of a policy engine in a zero trust architecture:

  • Uses multiple signals
  • Provides a secure and flexible access control mechanism
  • Adapts to the resources being requested

5. Authenticate & authorise everywhere

Any authentication and authorisation activities should consider multiple signals, such as:

  • Device health
  • Device location
  • User identity
  • Status to evaluate the risk associated with the request.

Because the network is assumed to be hostile, a zero trust architecture ensures that all connections that access your organisation’s data or services are authenticated and authorised.
6. Focus your monitoring on users, devices and services

In a zero trust architecture, monitoring should always link back to the policies you have set with regards to gaining assurance. A zero trust monitoring strategy focuses on individual users, user behaviour, devices and services to help organisations establish their health.

7. Don’t trust any network, including your own

In a zero trust architecture, traditional user protections such as phishing protection and malicious website filtering may be implemented differently and may require different solutions. A key principle of zero trust is to remove inherent trust from any network between a device and a service—including the local network. Any communication over a network to access data or services should use a secure transport protocol to ensure that the traffic is protected in transit and is less susceptible to threats.
 
8. Choose services designed for zero trust

Not all services support zero trust, which means that they may require additional resources to integrate zero trust architecture. This causes an increased support overhead, so it’s advisable to consider alternative services and products that have been designed with zero trust architecture in mind. Products with zero trust capabilities allow for easier integration and simpler interoperability.

Adopting zero trust principles in your organisations

If you are new to zero trust or if you’re unsure whether it is the right network architecture for your needs, it’s a good idea to engage with a digital transformation partner to help you design and review a zero-trust architecture that meets your organisation’s specific requirements.

Matthew Margetts

Smarter Technologies tracks, monitors and recovers assets across the globe in real time, providing asset tracking systems to the open market and fulfilling the world’s most complex asset tracking requirements. Our services cover a vast array of business sectors, products and equipment from container or pallet tracking to military-grade devices; and can be used across a broad spectrum of industries.

As a leading IoT company, we also provide smart building solutions for modern businesses, offering wire-free, battery-powered and low-cost IoT smart sensor technology. Our solutions will put an end to scheduled maintenance and help businesses utilise their building’s efficiency, benefitting from real-time alerts and facilities management tools that will bring them into the 21st century.

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors

    June 19, 20266 Mins Read

    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals

    June 19, 20265 Mins Read

    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day

    June 19, 20263 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}