Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»NSA Publishes New Zero Trust Implementation Guidelines
News

NSA Publishes New Zero Trust Implementation Guidelines

Team-CWDBy Team-CWDFebruary 2, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A new set of Zero Trust Implementation Guidelines (ZIGs) detailing how organizations can progress to target-level zero trust maturity has been released by the US National Security Agency (NSA).

The guidance introduces Phase One and Phase Two of the ZIGs, designed to support the US Department of War’s (DoW), previously the Department of Defense, zero trust framework and the wider US government cybersecurity strategy.

The newly published phases are intended to move organizations from the Discovery stage through to target-level implementation. They outline required activities, dependencies and outcomes while allowing flexibility for firms to tailor adoption based on operational needs and constraints.

Phase One establishes a secure baseline. It defines 36 activities that support 30 zero trust capabilities, helping organizations build or refine foundational controls before deeper integration. Phase Two builds on this work with 41 activities that enable 34 additional capabilities, focusing on integrating core zero trust solutions across component environments.

The phased approach reflects a modular design rather than a fixed roadmap.

Brian Soby, CTO and co-founder of AppOmni, said this structure reinforces the idea that zero trust is not a one-time deployment. “[It] is an operating model, not a product,” Soby said, noting that policy decisions must be continuously evaluated and enforced as conditions change.

Read more on Zero Trust: Risk of AI Model Collapse to Drive Zero Trust Data Governance, Gartner Says 

Shifting From Perimeter Security to Continuous Evaluation

The guidance reinforces a shift away from perimeter-based security toward continuous authentication and authorisation of users, devices and applications. Zero trust operates on the principles of “never trust, always verify” and “assume breach,” an approach increasingly viewed as necessary as cyber threats evolve.

Soby said one of the strongest aspects of the guidance is its focus on activity after authentication.

“Continuous evaluation has to happen after login, not just at login,” he said. According to Soby, many successful attacks now occur post-authentication, where basic identity checks and device posture assessments offer limited protection without visibility into what happens inside applications.

The guidelines draw on several established frameworks developed under Executive Order 14028, including NIST Special Publication 800-207, the CISA Zero Trust Maturity Model Version 2.0 and the DoW Zero Trust Reference Architecture. The NSA developed the guidelines in close coordination with the DoW CIO to organize 152 Zero Trust activities into structured phases.

However, Soby warned that many organizations still misapply zero trust by focusing too heavily on network access controls alone. Treating zero trust network access as a complete solution overlooks how applications make and enforce their own access decisions.

“Any zero trust architecture that leaves visibility and management of the application policy decision points out of the architecture is expensive and grossly insufficient,” he said.

The NSA said the current guidance is intended to help skilled practitioners achieve target-level zero trust maturity, with additional advanced phases potentially developed in the future.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services
Next Article Beware of Winter Olympics scams and other cyberthreats
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Chronology of a Skype attack

February 5, 2026

In memoriam: David Harley

November 12, 2025

How the always-on generation can level up their cybersecurity game

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.