Glossary

Zero trust

Zero trust is the principle that being inside the network grants no privilege. Every request is authenticated and authorised on its own merits, whether it comes from the office, a laptop in a café, or another service in the same data centre.

It replaces the older model of a hardened perimeter around a trusted interior, which fails in one move: an attacker who gets in anywhere gets everything, and remote work and cloud services have made the perimeter largely fictional anyway.

In practice it means strong identity for people and services, least-privilege access to each resource, and the assumption that any component may already be compromised. It is a direction rather than a product, whatever a vendor may be selling.

← Back to the glossary