Learning Hub › Deep Dives › Zero Trust
Deep Dive 01 · Interactive guide
Zero Trust Cloud Architecture
"Never trust, always verify." Zero Trust drops the idea that anything inside the company network is safe. Every request, from every user, device and workload, is checked against policy before it gets access, and checked again while it runs. This page walks you from the basic idea to the real frameworks (NIST SP 800-207, CISA's Zero Trust Maturity Model) with hands-on models you can play with.
Castle-and-moat vs Zero Trust
The old model is a castle: a strong wall (firewall, VPN) and everyone inside is trusted. The trouble is that attackers rarely break the wall. They phish one employee and walk in through the front door. Pick a model, then phish a laptop and watch how far the attacker gets.
Press "Phish a laptop" to start the attack.
The 7 tenets of NIST SP 800-207
NIST's Zero Trust Architecture standard (SP 800-207) boils the idea down to seven tenets. Open each one for the plain-words version and an everyday example.
Access-decision simulator
Be the Policy Engine. Set who is asking, from what device and where, and what they want. The engine weighs every signal and returns one of four answers. Try the presets first, then change one signal at a time and see what happens.
Why: the engine's trace
CISA Zero Trust Maturity Model v2.0
CISA's model breaks Zero Trust into five pillars and four stages, from Traditional to Optimal. Nobody jumps straight to Optimal: organisations move each pillar forward one stage at a time. Pick a pillar to see what each stage looks like.
Cross-cutting capabilities: they run across all five pillars
Self-check: where is your organisation?
Pick the stage that best matches today for each pillar. Answer honestly; this stays in your browser.
Your profile
Micro-segmentation in a hybrid cloud
Most companies run a mix: an on-prem data centre plus one or more cloud VPCs joined by VPN or peering. Joined networks are convenient, and they also let an attacker roam. Micro-segmentation draws a tiny boundary around each workload and only allows the flows that the business needs, written as rules about identities (which service, which user group) rather than IP addresses.
Click a flow to test it
A practical roadmap
Zero Trust is a journey, not a product. NIST's National Cybersecurity Center of Excellence proved this in SP 1800-35 (final, June 2025): it built 19 example architectures with 24 vendors, each mixing existing tools rather than buying one box. A sensible order of work looks like this.
Myth or fact?
Five statements you will hear in meetings. Decide for each.
Sources & further reading
- NIST SP 800-207: Zero Trust Architecture
The tenets, the PE / PA / PEP model and deployment approaches.
- NIST SP 1800-35: Implementing a Zero Trust Architecture
NCCoE practice guide with 19 example builds from 24 vendor collaborators.
- CISA Zero Trust Maturity Model v2.0
Five pillars, three cross-cutting capabilities, four maturity stages.
- OMB M-22-09: Moving the U.S. Government Toward Zero Trust
The federal strategy, including phishing-resistant MFA (archived copy).
Building pipelines too? Zero Trust's Applications & Workloads pillar expects security testing inside CI/CD. See it in action in the SAST in CI/CD lab, or continue with Threat Intelligence & MITRE ATT&CK.