Zero Trust is not a product, a technology, or a vendor category. It is an architectural philosophy built on a single foundational principle: never trust, always verify. Every access request regardless of whether it originates from inside or outside the traditional network perimeter must be authenticated, authorized, and continuously validated.
NIST Special Publication 800-207 provides the most authoritative and vendor neutral definition of Zero Trust Architecture (ZTA). Published in August 2020, it defines the core tenets of Zero Trust, describes the logical components of a ZTA, and provides deployment models for organizations at different stages of their Zero Trust journey.
The seven tenets of Zero Trust defined in NIST SP 800-207 form the conceptual foundation of any implementation. These include treating all data sources and computing services as resources; securing all communication regardless of network location; granting access to individual enterprise resources on a per-session basis; determining access to resources by dynamic policy; monitoring and measuring the integrity of all enterprise assets; enforcing strict authentication and authorisation before granting access; and collecting information about assets, network traffic, and access requests to improve security posture.
For most enterprise organisations, the practical implementation of Zero Trust begins with identity. Entra ID Conditional Access, combined with MFA and device compliance policies, provides the access control enforcement point for cloud resources. Network segmentation using micro-segmentation tools or ZTNA platforms such as Zscaler Private Access (ZPA) extends Zero Trust principles to application access.
Zscaler Internet Access (ZIA) provides the Zero Trust equivalent of traditional secure web gateway and next-generation firewall functionality, inspecting all internet-bound traffic from users regardless of location. Combined with ZPA for private application access, the Zscaler platform implements the Zero Trust Network Access (ZTNA) model defined in NIST SP 800-207.
FortressPoint conducts Zero Trust maturity assessments against the NIST SP 800-207 framework, producing a structured gap analysis and roadmap for organizations at any stage of their Zero Trust journey. Our assessment covers identity, device, network, application, and data pillars, providing a prioritized implementation plan aligned to risk and business objectives.
Speak with a FortressPoint consultant — we engage with specific questions, not just general enquiries.