Skip to content

Zero Trust

What is Zero Trust?

A security model that assumes no user, device, or network should be trusted by default, even those inside the corporate perimeter. Requires continuous verification for every access request.

Information Security

What the standards actually require on zero trust

Requirements naming zero trust across 6 standards, quoted from the control text.

Kuwait NCF Protect function (Access). Access Control and Identity Management aligned with NIST SP 800-53 AC family + ISO 27001 A.9 + Zero Trust principles.

KNCF-Protect-Access-Control-IAM-Privileged-MFA-Zero-Trust-Identity-Lifecycle-IAG-PAM · Kuwait NCF Protect + Access Control + IAM + Privileged + MFA + Zero Trust + Identity Lifecycle

Establish zero trust governance including strategy, roadmap, funding, and measurement against maturity stages.

ZTMM-CROSS-3 · Governance for Zero Trust
FISMA1 control

FISMA coordination with CIRCIA + Zero Trust + Executive Orders + OMB Memoranda. CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022): Final Rule effective 2026;

FISMA-CIRCIA-ZTA-EO14028 · CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda

Per EO 14028 + OMB M-22-09: Zero Trust Architecture Adoption + federal cybersecurity modernization + identity + device + network + application + data pillars.

USEO14028-2 · Zero Trust Architecture and Federal Cybersecurity

Questions people ask about zero trust

What is Zero Trust?
A security model that assumes no user, device, or network should be trusted by default, even those inside the corporate perimeter. Requires continuous verification for every access request.
Why is Zero Trust important for compliance?
Zero Trust is a key concept in Information Security. Understanding zero trust helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Zero Trust?
Key concepts related to Zero Trust include Least Privilege, MFA (Multi-Factor Authentication). Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Zero Trust?
Zero Trust appears in the requirement text of Japan FSA Cybersecurity Guidelines for Financial Institutions, Kuwait National Cybersecurity Framework, CISA Zero Trust Maturity Model, FISMA, US Executive Order 14028 - Improving the Nation's Cybersecurity. Across these standards we have identified 13 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Zero Trust?
Explore our compliance framework pages to see how zero trust applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Zero Trust applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.