Skip to main content
Book 07 · SecurityPage 49 of 50

Zero Trust

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/zero-trust

In short

Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.

What is zero trust?

Traditional network security works like a castle with a moat: everything inside the company network is trusted, and a firewall protects the edge. Zero trust drops that assumption and follows the principle never trust, always verify. Every request to an application or service must prove who is making it and whether it should be allowed, whether it comes from the office, a home network, or another server in the same data center.

In practice, zero trust combines several controls: strong authentication for users, ideally with phishing-resistant MFA; checks on device health, such as whether the operating system is up to date; fine-grained authorization with least privilege; encryption of all traffic, including between internal services with mutual TLS; and continuous monitoring. Access decisions are made per request and per resource, rather than once when someone connects to a VPN.

Think of a modern office building where your badge must be scanned at every door, not just the front entrance, and the system also checks the time and which floor you work on. If an attacker steals one laptop or breaks into one server, they cannot freely move sideways through the network, an attack technique called lateral movement.

Zero trust is a strategy and architecture, described in guidance such as NIST SP 800-207, not a single product you can buy, even though many products carry the label. It also does not mean distrusting employees; it means not treating network location as proof of trust. Organizations usually adopt it gradually, starting with strong identity and MFA, then segmenting networks and protecting the most sensitive applications first.

Key takeaways

  • Zero trust assumes no user, device, or network is trusted by default.
  • Every request is authenticated, authorized, and encrypted.
  • Being inside the corporate network grants no automatic access.
  • Least privilege and segmentation limit lateral movement after a breach.
  • Zero trust is an architecture and strategy, not a single product.

Example

Verifying every service-to-service request (Express)javascript
// Every request is verified, even from "internal" services on the same network
// (verifyServiceToken and policy are defined elsewhere)
app.use(async (req, res, next) => {
  // 1. Who is calling? Check a signed, short-lived token, not the source IP
  const caller = await verifyServiceToken(req.headers.authorization);
  if (!caller) return res.sendStatus(401);

  // 2. May this caller perform this action on this resource?
  if (!policy.allows(caller, req.method, req.path)) {
    return res.sendStatus(403);
  }

  req.caller = caller;
  next();
});

Readers ask

What does never trust, always verify mean?

It is the core idea of zero trust: no request is trusted just because of where it comes from. Each one must be authenticated and authorized, even if it originates inside the company network.

Does zero trust replace VPNs?

Often, yes. Zero trust access tools give users access to specific applications after verifying their identity and device health, instead of placing them on the whole internal network the way a traditional VPN does.

Is zero trust a product?

No. Zero trust is a security model that combines identity, device checks, least-privilege access, encryption, and monitoring. Vendors sell tools that help implement it, but no single product makes an organization zero trust.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings