All Articles Technology Security How to implement zero-trust security in your organization

How to implement zero-trust security in your organization

Here are seven steps for implementing zero-trust security, from strengthening identity and device controls to securing applications, monitoring threats and extending continuous verification to AI systems.

6 min read

SecurityTechnology

(Olivier Le Moal/Getty Images)

Traditional cybersecurity models often assume that organizations can trust users and devices inside the corporate network more than those outside it. As more organizations adopt cloud services, remote work, mobile devices, SaaS applications and distributed infrastructure, that approach has become difficult to defend.

The zero-trust model uses a different approach: never trust devices and apps based solely on network location or asset ownership. Instead, you need to continuously evaluate whether a user, device, application or other entity should have access to a particular resource. 

The National Institute of Standards and Technology defines zero-trust architecture as an approach that focuses security controls on users, assets and resources rather than networks. Implementing zero trust is not simply a matter of purchasing a new security product. It is an architectural and operational transformation. Here are seven steps you can take to implement zero trust at your organization.

  1. Develop a zero-trust strategy

NIST’s latest implementation guidance, SP 1800-35, recommends using practical implementation scenarios rather than attempting an organization-wide transformation all at once. The guide documents example zero-trust implementations developed in collaboration with industry partners.

You should begin your zero-trust program by defining what you mean by zero trust and by identifying the business resources that need protection. Critical applications, data repositories, infrastructure, identities, endpoints and network connections should be inventoried.

Then, you should identify high-value assets and sensitive workflows. For example, your organization might initially focus on privileged administrator accounts, access to financial systems, customer data or critical cloud applications.

  1. Build a strong identity foundation

Your authentication policy and requirements should be robust to withstand credential theft and other common attack methods.

Laying a strong identity foundation requires centralized identity and access management, multifactor authentication, single sign-on and processes for rapidly provisioning, modifying and deactivating accounts.

Your security program should use the least-privilege principle. This requires that administrators, employees, contractors and applications receive only the access necessary to perform their roles. Where possible, you should employ just-in-time or temporary privileges rather than permanent administrative access.

  1. Maintain an accurate device inventory

Zero trust requires an accurate understanding of the devices requesting access, not simply the identities of the people using them.

Your organization should maintain an accurate inventory of laptops, smartphones, servers, cloud workloads, internet of things devices and other endpoints. You should integrate endpoint management, endpoint detection and response capabilities with your identity and access controls.

Your security policies need to take into account whether a device is managed, encrypted, patched, running approved security software or exhibiting suspicious behavior.

  1. Secure applications and data

Zero trust protects resources, not merely networks. This requires an organization to identify who and what can access individual applications, services, databases and datasets.

Your zero-trust program should segment sensitive applications and systems. This will prevent an attacker who compromises your network from accessing sensitive information and applications. Micro-segmentation limits lateral movement within networks by restricting communication between workloads and resources.

Data should be classified according to sensitivity and protected through appropriate encryption, access controls, monitoring and data-loss prevention mechanisms.

NIST’s SP 1800-35 includes implementation approaches involving identity governance, micro-segmentation, software-defined perimeter technologies and secure access service edge architectures.

  1. Apply context-aware access policies

A zero-trust access decision should consider more than username and password. Depending on the resource and risk, your policy should incorporate identity, device health, location, application, requested resource, time, behavioral indicators and other contextual information.

For example, an employee trying to access a low-risk application using a corporate laptop might not have a problem. But that same employee, when requesting access to a sensitive database from an unmanaged device, could be denied or required to complete additional authentication.

Your objective should be to apply controls proportionate to risk, not to make every access request burdensome for users.

  1. Continuously monitor and respond

Rather than a one-time implementation, zero trust is an ongoing process. Your organization should continuously collect and analyze identity, endpoint, network, application and cloud telemetry.

You should integrate relevant security data into your security information and event management tool and security operations processes. In addition, you should establish automated responses for events such as compromised credentials, anomalous privilege escalations or devices that suddenly fail to meet security requirements.

The Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model organizes zero-trust capabilities around five major pillars — identity, devices, networks, applications/workloads and data — with visibility and analytics, automation and orchestration, and governance serving as cross-cutting capabilities.

  1. Measure progress and implement incrementally

Zero-trust implementation is not all-or-nothing. Instead, you should approach zero trust as a gradual process that includes measurable milestones.

Useful metrics include MFA adoption, percentage of managed devices, privileged-account coverage, number of applications protected by granular access policies, segmentation coverage, policy violations and mean time to detection and response.

You should begin with a manageable pilot, evaluate its effect on both security and user experience, address operational problems and then expand to additional applications and business units.

AI and zero-trust security

AI is reshaping the implementation of zero-trust security. Cyberattacks and defenses are moving faster, becoming more automated and more adaptive. On the threat side, attackers can scale phishing campaigns, create convincing synthetic identities and automate attempts to bypass security controls using AI. 

At the same time, your organization can use AI to boost zero-trust security by quickly analyzing large volumes of security signals, identifying unusual behavior and automating responses to potential compromises. 

To accommodate AI, your organization should expand the scope of its zero-trust implementation beyond human users. You need to use unique identities, least-privilege permissions, life-cycle controls and continuous monitoring for AI agents, plug-ins and other AI-based workloads. Your zero-trust strategy should evolve toward continuous verification, strict access controls and real-time risk assessment for both people and AI systems. 

Making zero-trust operational

The fundamental principle behind zero trust is simple: access should be authorized based on current risk.

For your security team, implementing that principle requires coordinated changes to several tools and systems. These include identity management, endpoint security, network architecture, application security, data protection, monitoring and governance. The key to successful zero-trust implementation is having a well-thought-out, phased approach.

If you like these insights on cybersecurity, sign up for the ISACA SmartBrief on Cybersecurity, a daily look at the top news and workforce education topics.