The canonical document. Three core components:
Seven tenets. Three deployment models: enhanced identity governance, micro-segmentation, SDP.
152 zero trust activities across seven pillars. Thunderdome hit 152/152 by May 2025. All defense components must achieve target ZTA by FY2027.
Five pillars: Identity, Devices, Networks, Apps/Workloads, Data Three cross-cutting: Visibility/Analytics, Automation/Orchestration, Governance Four stages: Traditional, Initial, Advanced, Optimal
Core architecture: Device Inventory DB, Device Identity, SSO, Access Control Engine, Access Proxy, Trust Inferrer. No VPN required. All internal apps through access proxy.
WireGuard-based mesh VPN through NAT/firewalls. Zero-config encrypted networking.
Headscale: open-source self-hosted control server alternative.
Practical approach: