How to Start Applying Zero Trust Architecture

TL;DR
Start a zero trust program by gaining visibility into assets, resources, users, devices, and business processes, then map access requirements and identify security gaps. Deploy changes incrementally, beginning with familiar access patterns and progressively tightening policies, device checks, encryption, and enforcement while using integrated, extensible technologies to reduce security blind spots without unnecessarily increasing user friction.
Transcript
I'm excited to introduce our next speaker and session, Applied Zero Trust: Actionable Steps You Can Take Right Now. Our speaker is Jennifer "JJ" Mannella, who is an internationally recognized authority on network and wireless security, an author and public speaker. A network architect turned advisory CISO and InfoSec leader. In the past fifteen yea... Read More
Key Insights
- Zero trust is an architecture and access model, not a single product. Its idealized framework uses a policy decision point as the central decision-making function and multiple policy enforcement points throughout networks, endpoints, applications, and cloud environments to carry out access decisions.
- Policy enforcement points can be hardware, software, or service integrations. Firewalls, switches, routers, endpoint agents, resource agents, and software-service APIs can all enforce policies, allowing organizations to apply a shared architectural concept across on-premises systems, remote access, and cloud resources.
- Incremental deployment is a practical way to begin zero trust. An organization can initially reproduce a familiar virtual private network enclave, preserve existing resource access, and later make policies more granular as administrators learn which networks and resources each user actually needs.
- Zero trust can improve security while reducing user friction. A common agent can support access from on-premises and remote locations, removing the need for employees to follow different connection procedures while administrators strengthen policies, encryption, inspection, and device posture controls behind the scenes.
- Visibility is the starting point for a zero trust journey. Security teams need to understand their assets, resources, access patterns, and business processes because systems and activities that remain unknown cannot be adequately mapped, evaluated, or protected through access policies.
- Automation, integration, and platform extensibility are critical to a long-term zero trust strategy. The required capabilities will not come from one product or necessarily one vendor, so technologies must exchange information and support interchangeable enforcement, decision, and resource components.
- Zero trust applies beyond people connecting to networks and resources. The same architectural concept can govern server-to-server, service-to-service, microservice, and serverless interactions, including access between applications and data sets located either in cloud environments or on-premises infrastructure.
- Business process review is part of zero trust planning. Long-established procedures may reflect habit rather than necessity, so organizations should examine how work is performed and determine whether processes can be redesigned before translating them into technical access rules and controls.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How do organizations start implementing zero trust?
Organizations should start by gaining visibility into their assets, users, devices, resources, access relationships, and business processes. They can then map what exists, analyze gaps, and determine which access is genuinely required. Implementation can proceed in phases, beginning with familiar remote-access behavior and gradually adding granular restrictions, stronger encryption, inspection, and advanced device posture checks.
Q: What is a policy decision point in zero trust?
A policy decision point is the policy engine that decides whether a subject should receive access to a requested resource. In the ideal zero trust framework, it acts like a central brain whose decisions are enforced in different parts of the network and application environment. The subject can include a user together with the device being used.
Q: What is a policy enforcement point in zero trust?
A policy enforcement point is the component that applies an access decision near a user, device, network, application, or protected resource. It can be a firewall, virtual private network terminator, switch, router, endpoint agent, resource-side agent, or API integration with a software service. Multiple enforcement points can operate across on-premises and cloud environments.
Q: Can zero trust be introduced without immediately changing user access?
Zero trust can be introduced incrementally by first reproducing an existing enclave or virtual private network access model. Users may initially retain access to the same resources through an upgraded or replacement agent. Administrators can then tighten policies behind the scenes, especially for networks users never needed, often without creating a noticeable change in their normal work.
Q: How can zero trust reduce user friction?
Zero trust can reduce friction when one access agent and policy model work across on-premises and remote environments. Employees no longer need separate procedures for accessing resources from the office and from home. At the same time, administrators can improve encryption, inspect protected tunnels, evaluate device posture, and restrict unnecessary access without repeatedly interrupting the user.
Q: Why is asset visibility important for zero trust?
Asset visibility is important because an organization cannot protect systems, resources, and processes that it cannot see or does not know exist. Building an inventory helps security teams understand what must be accessed, who or what needs access, and where gaps remain. That understanding provides the foundation for mapping relationships and creating appropriate zero trust policies.
Q: Can one vendor provide an entire zero trust solution?
The session states that organizations should not expect one product, or even one vendor's product set, to provide everything required for zero trust. A long-term strategy therefore depends on automation, integration, and extensibility. Platforms and controls should support connections among policy functions, enforcement technologies, endpoints, applications, software services, and other cloud or on-premises resources.
Q: Does zero trust apply to applications and services as well as users?
Zero trust applies to more than users accessing networks and resources. The same concept can control server-to-server and service-to-service communication, as well as interactions involving microservices and serverless architectures. It can govern how applications and data sets access one another whether those resources operate in cloud environments, on-premises infrastructure, or a combination of both.
Summary & Key Takeaways
-
Zero trust architecture separates access decisions from enforcement. A policy decision point determines whether access should be permitted, while policy enforcement points apply that decision through components such as firewalls, switches, routers, endpoint agents, resource agents, and API connections to software services and other cloud resources.
-
Organizations can begin incrementally by replacing or upgrading familiar remote-access mechanisms while preserving the access employees already use. Administrators can then tighten policies behind the scenes, restrict unnecessary network reach, strengthen encryption, inspect protected tunnels, and introduce more advanced device posture checks without forcing disruptive changes on users all at once.
-
A sustainable zero trust strategy starts with visibility into assets, access relationships, and business processes. It must also account for on-premises networks, remote workers, cloud services, infrastructure, platforms, and communication between applications or services. Because no single product covers every requirement, integration, automation, and extensibility remain essential design considerations.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator