Zero trust

Last updated | September 25, 2026 | 8 min read

Verify trust at every interaction stage across your network and systems

Trust no one. Verify everything. When it comes to cybersecurity and protecting your expanding attack surface, that's more than a catch-phrase. It's the way you should approach access to your network, systems and assets.

Zero trust security does just that. It's a strategic way to approach your cybersecurity practice — from a position of trust elimination and continuous verification — to ensure controls are in place to verify trust at every stage of an interaction across your network and systems. With traditional on-prem IT systems, this has generally been managed by hardware and other network tools to build an access perimeter, but those practices are no longer enough in a cloud-first or hybrid work environment.

In this zero trust knowledgebase, we take a closer look at what zero trust is, how it works and why it's a critical component of a mature, best-practice focused cybersecurity strategy.

Zero trusts given

Tenable One will help accelerate your zero trust journey. With foundational visibility into all assets across your modern attack surface, vulnerability prioritization and Active Directory (AD) security — all in one exposure management platform — your security team will have what it needs to stop lateral movement and prevent attacks before they happen.

Rethink your security with a zero trust approach

The modern business world is constantly evolving. To keep up, your attack surface is evolving along with it. As both become more complex, it's no longer possible to define modern attack surfaces with a logical perimeter.

So, how do you now effectively control and secure your network, applications and users? The answer is zero trust.

Because of increased use of cloud services, software, applications and new interconnected devices, security teams are finding it ever-more difficult to get their arms around everything that makes up the attack surface. Without that knowledge, most have limited visibility into where they have cyber risk so they can't make plans to address it.

Zero trust is a strategy that can help your security teams adapt to this complex environment. In this solution overview, learn more about how you can:

  • Identify misconfigurations and vulnerabilities on your network
  • Apply best practice recommendations to address security weaknesses
  • Identify and resolve often-overlooked risks in your Active Directory (AD)
  • Evolve your risk-based vulnerability management practices to support zero trust

Tech insights

How Tenable helps federal agencies meet CISA's binding operational directive 23-01

Federal agencies are required to comply with the Binding Operational Directive (BOD) 23-01, a compulsory direction about safeguarding federal information and information systems. Through BOD 23-01 agencies must conduct continuous and comprehensive asset visibility, focusing on asset discovery and vulnerability enumeration. But what exactly does that mean for your agency?

In this piece, learn more about asset discovery and vulnerability enumeration as it relates to BOD 23-01 mandates, including an overview of new requirements and insight into how Tenable can help address them.

The path to zero trust: is it time to rethink what we're calling a vulnerability?

Before the pandemic, organizations were making slow moves toward adopting zero trust, but post-pandemic has certainly accelerated implementation speed. Still, some organizations are slow to get on board. However, today's modern business environments, which now include cloud services, software and applications, coupled with more workers working from home than pre-pandemic means traditional network perimeters just aren't enough to protect enterprises.

Some organizations are hesitant to move toward zero trust out of fear it's just too complex to implement, especially for large organizations. But should the benefits of zero trust and the simplicity of the concept outweigh those concerns?

There are some key factors to consider before answering:

  • Is there a solution for zero trust?
  • How can I migrate our existing IT ecosystem to meet zero trust principles?
  • How do I address security concerns?

In this piece, learn more about those three core questions and take a closer look at four factors that can help give you a clearer picture about the benefits of implementing a zero-trust architecture.

Eliminating attack paths in Active Directory: a closer look at preventing privilege escalations

Attackers love to steal identities and credentials because once they successfully get access to your identity systems, they can make lateral movements throughout your network and escalate privileges, often without you knowing they're there.

An often overlooked source of this type of access begins in Active Directory (AD), a place where attackers hope you've missed unpatched vulnerabilities and are unaware you have misconfigurations or other security issues.

As part of your zero trust security strategy, it's important to give your Active Directory the attention it deserves. This white paper takes a closer look at how attackers can take advantage of Active Directory.

Read more to learn:

  • Why Active Directory is a crucial part of attack paths
  • How attackers can take advantage of vulnerabilities and escalate privileges
  • How you can detect and eliminate attack paths before attackers exploit them

Frequently asked questions about zero trust

Are you new to zero trust? Do you have questions about zero trust but not sure where to start?
Check out this FAQ:

What is zero trust?

Zero trust, according to NIST, is “an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources.”

Why is it called zero day?

In context of vulnerability assessment and vulnerability management, a vulnerability may be referred to as zero day because the software or application developer or vendor has had zero days to remediate the vulnerability.

Why is zero trust important?

Zero trust is important because the traditional way of protecting enterprises — by building and defending a network perimeter — is no longer enough for your modern attack surface. Zero trust is a proactive cybersecurity approach. It removes implicit trust for your users and assets enabling your organization to apply identity and access protocols for every connection or session.

How does zero trust work?

Zero trust works by assuming there is no implicit trust for any of your assets or users. It removes the traditional perimeter approach that assumes trust could be given for assets and users based on physical or network location or who owns an asset. Instead, zero trust uses continuous authorization and identification for users and devices before users or assets can access your systems or network.

What is zero trust architecture?

According to NIST, zero trust architecture “uses zero trust principles to plan industrial and enterprise infrastructure and workflows.”

Are zero day and zero trust the same?

No. Zero day and zero trust are not the same. Zero day is a term used to describe a vulnerability that has only recently been discovered or disclosed and doesn't yet have a patch to remediate the security issue. Zero trust is a cybersecurity approach to help protect your organization from zero-day exploits.

What are the main components of zero trust?

Zero trust eliminates implicit trust for access to your systems, data and network. Instead, it assumes that anyone (or any device) from anywhere (in and out of your network) has the potential to be an attacker. As such, zero trust is a process that will instead verify user identity and access privileges before opening a session. Similar to least-privilege access, administrators only grant users the minimum amount of access necessary to complete functions or roles. Zero trust also puts access restrictions on devices, regardless of if they're within or outside of a network. Instead, with zero trust, you must authorize every device. Many organizations will also implement micro-segmentation across networks to limit system-wide access, granting access to only certain parts of the network as needed.

What are the benefits of zero trust?

There are many benefits of zero trust. One of its biggest benefits is that zero trust is more effective for today's modern attack surface, which now includes a range of devices and services both on-prem or in the cloud. Zero trust doesn't just help you protect your attack surface, it's also a way to reduce it. Overall, implementing zero trust architecture should help reduce some of your cyber risk and help you be better prepared to detect and respond to security incidents as they happen.

What are some disadvantages of zero trust?

While the benefits outweigh the disadvantages of zero trust, there are some to consider. One of the most commonly discussed disadvantages is the fear some organizations have that it's just too complex to implement. While there may be some truth in that, implementation can be made that much harder if your organization is still taking a legacy approach to vulnerability management and remains focused on security defenses that don't work for most modern attack surfaces, such as maintaining a traditional perimeter-based approach. To implement zero trust, your organization will need to shift left to a more proactive, risk-based strategy for asset and vulnerability management.

What is the CISA zero trust maturity model?

The CISA Zero Trust Maturity Model is a framework organizations can use to transition to a zero trust architecture. It is made up of five pillars and three capabilities based on zero trust. 

The five pillars: 

  1. Identity
  2. Device
  3. Network
  4. Application
  5. Data

Capabilities:

  1. Traditional
  2. Advanced
  3. Optimal

To learn more about each of these pillars and capabilities, download CISA’s pre-decisional draft of “Zero trust maturity model.”

What is zero trust network access (ZTNA)?

Zero trust network access (ZTNA) is similar to a VPN in that it enables access to systems and services, but does so in a secure way that takes into consideration user and asset identity before granting access. According to Gartner, a zero trust network access, “creates an identity- and context-based, logical access boundary around an application or set of applications.”

What are the basic tenets of zero trust?

According to NIST, there are seven basic tenants of zero trust:

  1. All data sources and computing services are resources.
  2. All communication is secure.
  3. Access is granted on a per-session basis.
  4. Access is determined by dynamic policy.
  5. Monitoring and measuring integrity and security posture of all assets.
  6. Dynamic and enforced resource authentication and authorization.
  7. Information collection on current state of assets, network infrastructure and communications and uses.

Take a closer look at these tenants in the NIST and the Basic Tenants of Zero Trust section below.

Tenable Connect community: your go-to resource for zero trust

While the concept of zero trust has been around for a while, some organizations are just beginning their zero trust journeys. If you are and have questions about zero trust and implementing zero trust architecture, join Tenable Connect community. It’s a great place to engage with other professionals interested in learning more about zero trust and how Tenable can help.

Rethink your security with zero trust

Is your organization implementing zero trust architecture as part of your overall cybersecurity strategy? You’ll need continuous insight into all of your assets and their vulnerabilities, Active Directory (AD) security to find and fix issues before attackers exploit them, and the ability to prioritize remediation based on risk. Tenable One has everything you need — all in a single platform.

NIST and the basic tenants of zero trust

NIST SP 800-207 helps enterprise security architects better understand zero trust, including a roadmap to help security practitioners implement a zero trust approach to their existing cybersecurity practices and deploy zero trust architecture.

Why is this important? Modern enterprises are increasingly complex. Core operational systems are no longer traditional IT hardware and software that sit safely behind a network perimeter. Today, organizations around the globe work with on-prem networks, systems and assets alongside cloud-based services, applications and software.

Legacy security practices, such as setting up firewalls to keep the bad guys out are no longer effective. That’s why the industry is moving toward adopting zero trust for all assets and users, no matter where they live.

According to NIST, zero trust security “assumes that an attacker is present in the environment and that an enterprise-owned environment is no different — or no more trustworthy — than any non-enterprise-owned environment.” As such, enterprises can no longer assume implicit trust and must continuously verify to manage and mitigate risks.

NIST’s seven core tenants of designing and deploying a zero trust architecture are:

  1. All data sources and computing services are considered resources.
  2. All communication is secured regardless of network location.
  3. Access to individual enterprise resources is granted on a per-session basis.
  4. Access to resources is determined by dynamic policy — including the observable state of client identity, application/service, and the requesting asset — and may include other behavioral and environmental attributes.
  5. The enterprise monitors and measures the integrity and security posture of all owned and associated assets.
  6. All resource authentication and authorization are dynamic and strictly enforced before access is allowed.
  7. The enterprise collects as much information as possible about the current state of assets, network infrastructure and communications and uses it to improve its security posture.

Want to explore these tenants in more detail? Download “NIST Special Publication 800-207 Zero Trust Architecture.” It includes:

  • A zero trust network view
  • Components of zero trust architecture
  • Deployment scenarios and use cases
  • Threats related to zero trust architecture
  • Zero trust and existing frameworks
  • Guidance on migrating to a zero trust architecture

Zero trust blog bytes

Tenable One

See Tenable One in action

Trust no one. Verify everything. Remove attack paths and secure your organization against cyberattacks.

See
Tenable
in action

See how Tenable can give your team the clarity to fix what matters, at the speed of AI.