Glossary / network identity concepts

Zero trust

Never trust, always verify. A VPN badge is not a day pass. Identity, device, path, and data each get asked again.

Zero trust control layersZero trust architecture as five stacked control layers: Identity, Device, Network, Application, and Data. Assume breach; authenticate and authorise each request. A VPN badge is not a day pass.IDIdentitywho is askingDEVDeviceis it healthyNETNetworkpath + segmentAPPApplicationDATADataOther layerFocalZERO TRUST / NEVER TRUST · ALWAYS VERIFYEach layer asks again. A VPN badge is not a day pass.Identity and data are the usual focals; the middle three still ask.

Zero trust is an architecture idea: assume breach, authenticate and authorise every request, minimise blast radius, log the path.

It is not a product. Buying a ZTNA box and leaving standing domain admin is a rebrand.

Start with identity (phishing-resistant MFA, least privilege), device health, and segmentation around crown jewels. Then argue about overlays.