Zero Trust Architecture ·

Zero trust, from strategy to operations. One playbook for architecture, roadmap, technology and governance.

Aligned to NIST SP 800-207, SP 800-53 Rev 5 and the CISA Zero Trust Maturity Model. Change the stage or click any component below.

Zero trust architecture · NIST SP 800-207 reference model
Maturity Stage

Explore the playbook

Executive summary

What zero trust means for the business

A one-screen brief: why we are doing this, which way we could go, and the decisions leadership has to make.

Why now

    What changes for people

      Decisions needed

        Where we are

        Taken live from the self-assessment page.

        Executive brief

        Delivery options & business case

        Three common ways to source the platform. None is right for everyone; the tradeoffs are what matter.

        Business case template

        Fill one of these in for each funded initiative so investment and sequencing decisions can be compared like for like.

        Foundation

        People, architecture & protected estate

        The three layers everything else in this model builds on. Click a tab to jump to it.

        Assess

        Where are we, and where do we need to be?

        Set current and target maturity for each pillar. Stages follow the CISA Zero Trust Maturity Model v2.0, with MO1–MO3 shown alongside. The gap view and the priority list update as you go.

        Presets
        PillarCurrentTargetGap

        Maturity Model

        Three maturity objectives, seven domains

        Pick a stage to see what changes in each domain as the program matures.

        Domain
        Maturity model

        Crosswalk to the CISA Zero Trust Maturity Model v2.0

        This page uses 7 pillars and 3 stages. CISA uses 5 pillars, 3 cross-cutting capabilities and 4 stages. Use this table to read one in terms of the other.

        Roadmap

        Pillars & initiatives

        Seven pillars, each progressing through the same three phases. Pick a pillar to see all of its initiatives; the current stage is highlighted.

        Pillar
        Continuous across all phases
        Sequencing

        Dependencies & milestone gates

        The roadmap only works in the right order. Each gate has entry requirements, what it unlocks and the evidence that it is done. The current stage's gates are highlighted.

        Sequencing

        Critical dependency chains

        Starting a later step before an earlier one is finished is the most common reason zero trust programs stall.

        End-to-end

        How zero trust works, request by request

        Click a step to see what happens at that stage of every single access request.

        Continuous feedback loop: telemetry & logs → analytics → threat intelligence → policy tuning → automation — feeding straight back into Verify.
        Technology options

        Capabilities, Microsoft and alternatives

        Each capability, the Microsoft option and established alternatives. Use it to spot what you already own, where tools overlap and where a specialist product earns its place. Vendor lists are examples, not endorsements.

        Pillar
        G5 in Microsoft 365 G5 / E5 Add-on separate license Azure usage-based Azure service Gap no full native equivalent

        Licensing and product names change often. Confirm current Microsoft 365 G5/E5 inclusions and vendor capabilities before using this for a purchase decision.

        Technology options

        Overlap to watch

        Places where a mixed Microsoft and third-party estate most often pays twice or enforces policy in two places.

        Workstream playbooks

        CASB, BYOD, SASE & SOAR

        The four workstreams that most often need architectural direction. Each one covers the phases, the decisions to settle early and the teams it depends on.

        Governance

        Architecture review, ownership & exceptions

        How designs get approved, who owns what, and how to say "not yet" safely when a control can't be met.

        Architecture review

        Every design that changes an access path goes through the same five steps.

        Exception process

        Exceptions are time-limited risk decisions, not permanent waivers.

        Governance

        Ownership & decision records

        Who is responsible for what, and how decisions are captured so later teams know what was decided and why.

        RACI

        R = responsible · A = accountable · C = consulted · I = informed. Adjust roles to your organization.

        Decision record template

        Log every significant architecture decision so later teams know what was decided and why.

        Measure

        Metrics & traceability

        Measurable criteria for progress and maturity, with a target at each stage. The current stage's targets are highlighted.

        MetricDefinitionMO1 targetMO2 targetMO3 target
        Measure

        Traceability thread

        Every delivered capability should trace back to an objective and forward to a control and a metric. Pick an example.

        Standards alignment

        NIST SP 800-207 & SP 800-53 Rev 5

        SP 800-207 defines the zero trust architecture; SP 800-53 supplies the controls that prove it. Each pillar below lists the controls that phase implements. Move the stage rail to see what each stage adds.

        SP 800-53 Rev 5 controls by pillar & stage

        Controls are cumulative: MO2 inherits MO1, MO3 inherits both. Enhancements are shown in parentheses, e.g. AC-2(1).

        Pillar

        This is an indicative mapping and does not replace your system security plan (SSP). Confirm control selection and tailoring against your SP 800-53B baseline and your organization's policies.

        Reference

        SP 800-207 · The seven tenets of zero trust

        What every tag on this page means. Hover a tag such as Tenet 6 or IA-2 anywhere on the page for a quick definition, or click it to jump here.

        From NIST SP 800-207 Zero Trust Architecture (2020), section 2.1, with what each tenet means in practice.

        Reference

        SP 800-207 · Components & deployment approaches

        The building blocks behind the architecture diagram, and the three ways NIST describes building it.

        Logical components

        The building blocks from section 3 that appear in the architecture diagram.

        SP 800-207 · Deployment approaches

        Section 3.1 describes three ways to build a zero trust architecture. Most enterprises combine them.

        Reference

        SP 800-53 Rev 5 · Control index

        Every control cited on this page, grouped by family, with where it is used. Numbers in parentheses are control enhancements.

        Control titles follow NIST SP 800-53 Rev 5. See the NIST publications for full control text, discussion and related controls.

        Why it matters

        Business value & outcomes

        Six outcomes the architecture delivers, each tracked by a metric — and the foundations every one of them depends on.