Zero Trust

Zero Trust is an architecture, not a product: every request is checked against who is asking, from what device, for what, and under what conditions. We help you get there in practical steps, starting with what you already own.

Security & compliance
Zero Trust
Covers
Architecture and roadmap, identity, device and network controls, monitoring
Serves
Onsite in New Mexico; remote engineering nationwide

Four Directions helps design and implement technology that supports security and compliance objectives. We do not provide legal advice, and we do not assess or certify compliance.

What changes

Traditional networks trust whatever is inside the perimeter. Once an attacker, or a compromised laptop, is inside, it can usually reach far more than it should. Zero Trust removes that implicit trust: access is granted per request, to one resource, based on identity, device health and context, and it’s re-evaluated as conditions change.

How a Zero Trust architecture decides one requestDiagram. A user on a device requests a resource such as an application, data or a server. The request passes through a policy enforcement point. The enforcement point asks a policy decision point, which weighs identity and multifactor authentication, device health, location and risk signals, data sensitivity, and recent activity, then answers allow, deny, or require more verification. Access is granted to that one resource only, for that session, and every decision is logged and fed back into future decisions.User on adeviceRequestPolicyenforcement pointOne resource,this sessionResourceapp, data or serverPolicy decisionallow, deny or verify moreaskdecideSignals weighed on every requestIdentity and MFADevice healthLocation and riskData sensitivityRecent activityLogs and monitoringEvery decision is logged andbecomes a signal for the next
How a Zero Trust architecture decides one requestDiagram. A user on a device requests a resource such as an application, data or a server. The request passes through a policy enforcement point. The enforcement point asks a policy decision point, which weighs identity and multifactor authentication, device health, location and risk signals, data sensitivity, and recent activity, then answers allow, deny, or require more verification. Access is granted to that one resource only, for that session, and every decision is logged and fed back into future decisions.User on a deviceRequestPolicy enforcement pointaskdecidePolicy decisionallow, deny or verify moreSignals weighed on every requestIdentity and MFADevice healthLocation and riskData sensitivityRecent activityOne resource,this sessionResourceapp, data or serverEvery decision is logged, and the logsbecome a signal for the next request.
Based on the logical components in NIST SP 800-207. The decision is made per request, so a stolen password alone, or a compromised device, no longer opens everything inside the network.

The pillars

CISA’s Zero Trust Maturity Model and DoD’s Zero Trust strategy both organize the work into pillars. In practice:

Identity

One identity per person, phishing-resistant multifactor authentication, least privilege and just-in-time administrative access.

Devices

Only managed, healthy devices reach company resources, and device health is part of every access decision.

Applications and workloads

Access per application rather than per network, secure configurations and strong authentication between services.

Data

Know where sensitive data lives, label it, and control sharing and downloads.

Networks

Segment so that one compromised system can’t reach everything, encrypt traffic, and replace broad VPN access where it makes sense.

Infrastructure

Hardened servers, hypervisors and cloud accounts, with administrative access separated and monitored.

Visibility and analytics

Central logs and alerts that someone actually reviews.

Automation and orchestration

Policies enforced consistently by tools rather than by memory.

Where to start

  1. Inventory People, devices, applications and where sensitive data lives.
  2. Strong identity Multifactor authentication everywhere, phishing-resistant for administrators, and no shared accounts.
  3. Device trust Manage and assess devices, and require healthy devices for sensitive applications.
  4. Least privilege Separate administrator accounts and remove standing access nobody needs.
  5. Segment and monitor Break up flat networks, log centrally and review what you collect.

Most organizations already own part of what they need, in Microsoft 365, in their firewall or in their endpoint tools. We start there before recommending anything new.

What Zero Trust isn’t

  • A single product you can buy. Vendors sell components; the architecture is how they work together.
  • A one-time project. Policies and signals keep evolving with your business.
  • Only for large enterprises. Small organizations often get further faster, because they have fewer systems.
  • A replacement for compliance requirements. It supports frameworks such as NIST SP 800-171, but doesn’t replace them.

Questions we hear

Do we have to replace our VPN?

Not necessarily, and not first. Many organizations keep a VPN for some uses while moving important applications behind identity- and device-aware access. Where a broad VPN gives everyone access to everything, narrowing it is often a quick win.

How long does it take?

The first steps, such as multifactor authentication everywhere and separate administrator accounts, usually take weeks. A full Zero Trust architecture is a multi-year roadmap for most organizations, delivered in useful stages.

Does Zero Trust help with CMMC?

Many Zero Trust practices, including multifactor authentication, least privilege, device management, segmentation and logging, also support NIST SP 800-171 requirements. They’re complementary, and we design them together.

What standards do you follow?

NIST SP 800-207 defines Zero Trust architecture, and CISA’s Zero Trust Maturity Model describes stages of progress. We use them as references, scaled to the size of your organization.

Sources: NIST SP 800-207, Zero Trust Architecture; CISA Zero Trust Maturity Model.

Discuss a Zero Trust roadmap

Tell us what you run today and what worries you most. We’ll suggest the first practical steps.