Zero Trust Security Model
Syllabusbasics of cyber security
The Zero Trust security model treats every request for a digital resource as potentially risky, irrespective of whether it originates inside or outside an organisation's network. It replaces location-based trust with explicit verification, narrowly limited access and repeated assessment of users, devices and sessions.
Access decision
Access is determined separately for each requested resource through a dynamic policy rather than granted broadly after entry into a trusted network.
- The system verifies the requester's identity using strong authentication and relevant credentials.
- It evaluates the security posture of the device, the sensitivity of the resource and contextual signals such as location or unusual behaviour.
- Authorisation follows least privilege, giving only the minimum permissions needed for the task.
- Access is generally granted per session and does not automatically create continuing entitlement to other resources.
Policy enforcement
A policy engine uses organisational rules and available security information to permit, deny or revoke access. A policy enforcement point stands between the requester and the resource, establishes an approved connection and blocks an unauthorised one.
- Communications are protected regardless of the requester's network location.
- Authentication and authorisation are completed before access to a resource is allowed.
- Network presence or ownership of a device does not by itself establish trust.
Continuous assessment and containment
Zero Trust collects security information and reassesses access when identity, device health or operating context changes. This continuous monitoring allows privileges to be reduced or sessions terminated when risk rises.
- Resource-specific controls restrict lateral movement if an account or device is compromised.
- Logging and behavioural analysis help detect anomalous access and improve later policy decisions.
- The model complements defence-in-depth by shifting protection from a trusted perimeter towards users, devices, applications and data.
How UPSC asks this
UPSC may ask how Zero Trust strengthens cyber security, how it differs from perimeter-based security, and how identity verification, least privilege and continuous monitoring limit the impact of breaches.
Keep reading
The news behind topics like this, explained every morning
Every morning Gyaanam reads The Hindu, the Indian Express and PIB and picks what matters for UPSC. Each story is written up against the syllabus line it belongs to. Your first 15 days are free.