GyaanamKnowledge for All
Back to Internal SecurityAll concepts

Zero Trust Security Model

Syllabusbasics of cyber security

Internal SecurityPublished 4 August 2026

The Zero Trust security model treats every request for a digital resource as potentially risky, irrespective of whether it originates inside or outside an organisation's network. It replaces location-based trust with explicit verification, narrowly limited access and repeated assessment of users, devices and sessions.

Access decision

Access is determined separately for each requested resource through a dynamic policy rather than granted broadly after entry into a trusted network.

  • The system verifies the requester's identity using strong authentication and relevant credentials.
  • It evaluates the security posture of the device, the sensitivity of the resource and contextual signals such as location or unusual behaviour.
  • Authorisation follows least privilege, giving only the minimum permissions needed for the task.
  • Access is generally granted per session and does not automatically create continuing entitlement to other resources.

Policy enforcement

A policy engine uses organisational rules and available security information to permit, deny or revoke access. A policy enforcement point stands between the requester and the resource, establishes an approved connection and blocks an unauthorised one.

  • Communications are protected regardless of the requester's network location.
  • Authentication and authorisation are completed before access to a resource is allowed.
  • Network presence or ownership of a device does not by itself establish trust.

Continuous assessment and containment

Zero Trust collects security information and reassesses access when identity, device health or operating context changes. This continuous monitoring allows privileges to be reduced or sessions terminated when risk rises.

  • Resource-specific controls restrict lateral movement if an account or device is compromised.
  • Logging and behavioural analysis help detect anomalous access and improve later policy decisions.
  • The model complements defence-in-depth by shifting protection from a trusted perimeter towards users, devices, applications and data.

How UPSC asks this

Mains

UPSC may ask how Zero Trust strengthens cyber security, how it differs from perimeter-based security, and how identity verification, least privilege and continuous monitoring limit the impact of breaches.

Keep reading

The news behind topics like this, explained every morning

Every morning Gyaanam reads The Hindu, the Indian Express and PIB and picks what matters for UPSC. Each story is written up against the syllabus line it belongs to. Your first 15 days are free.

Sign up