glossary

What is zero trust?

Zero trust is a security model that assumes no user, device, or network segment is trusted by default.

Build my personalized career plan

Zero trust is a security model that assumes no user, device, or network segment is trusted by default. Every access request is verified individually and granted the minimum access needed, even from inside the network.

What it means

NIST describes zero trust as a set of principles for making accurate, least-privilege access decisions while treating the network as potentially compromised. In plain terms, "never trust, always verify": identity and context are checked on every request rather than trusting anything just because it is already inside the firewall. It shows up in modern cloud, identity, and security roles.

Core source records

This table lists the page’s core content records and when they were checked. Claim-specific citations appear beside the relevant text and may not be repeated here.

IDSupportsSourceChecked
CIT-01Definition source for What is zero trust?National Institute of Standards and Technology — NIST CSRC Glossary2026-06-15

Ready to turn this decision into a plan?

RoleMath planner