Skip to content
Clear Infosec

Identity & Access

What is Zero Trust?

Also known as: Zero Trust Architecture

Zero trust is a security model based on the principle of never trust, always verify, where no user or device is trusted by default and every access request is authenticated, authorized, and continuously validated. It matters because it reduces the impact of compromised credentials and lateral movement by removing implicit trust inside the network.

Example

Even after a user logs in, access to a sensitive application still requires device health checks and re-verification of identity for each session.

Reference: NIST ↗

Related Clear Infosec services

Related terms

Have a question about zero trust in your environment? Talk to our team.