Intro to Zero Trust through continuous monitoring — NIST tenets, CISA pillars, enterprise ZT architecture, network-centric ZT, identity-based ZT, and automated policy monitoring.
Module 01
Introduction to Zero Trust
›Zero Trust history and drivers — evolution from perimeter-based security (castle-and-moat) to Zero Trust; major breaches that drove ZT adoption; regulatory and compliance pressures pushing ZT frameworks
›Zero Trust definition and core philosophy — NIST SP 800-207 definition: "never trust, always verify"; ZT vs. traditional implicit trust; ZT assumptions: network is always hostile, external and internal threats exist
›ZT business drivers — cloud adoption, remote workforce, BYOD, API-based integrations; ZT as a strategy (not a product); ZT ROI: reduced breach impact, reduced lateral movement, improved compliance posture
›Key ZT principles — least privilege access; micro-segmentation; continuous verification; assume breach; explicit verification of all access requests; data-centric rather than network-centric security
›ZT adoption landscape — CISA Zero Trust Maturity Model stages: Traditional, Initial, Advanced, Optimal; DoD ZTA reference architecture; ZT maturity assessment frameworks
Module 02
Zero Trust Tenets and Pillars
›NIST SP 800-207 seven ZT tenets — (1) all resources are treated as resources; (2) all communication is secured; (3) access is granted per-session; (4) access is determined by dynamic policy; (5) monitor integrity/security; (6) strict authentication/authorization; (7) collect and use information to improve security
›CISA ZT pillars — five pillars: Identity, Devices, Networks, Applications/Workloads, Data; how each pillar contributes to ZT posture; pillar interdependencies; CISA cross-cutting capabilities: Visibility/Analytics, Automation/Orchestration, Governance
›Identity pillar — identity as the new perimeter; IdP (Identity Provider) role; SSO, MFA, conditional access; privileged identity management (PIM/PAM); continuous identity verification; identity risk scoring
›Devices pillar — device health as access signal; endpoint detection and response (EDR); mobile device management (MDM); device trust models; certificate-based device identity; BYOD ZT controls
›Networks pillar — micro-segmentation and software-defined perimeter (SDP); network access control (NAC); east-west traffic inspection; macro-segmentation vs. micro-segmentation
›Data pillar — data classification and labeling; data loss prevention (DLP); encryption at rest and in transit; information rights management (IRM); data access auditing
Module 03
Applying Zero Trust
›ZT design methodology — current state assessment: identify assets, users, data flows, and trust zones; ZT gap analysis against CISA maturity model; prioritizing ZT initiatives by risk and business impact
›Protect surface identification — defining the Protect Surface (data, assets, applications, services — DAAS); contrast with attack surface; minimizing and monitoring the protect surface
›Define transaction flows — mapping how traffic flows to and around the protect surface; dependency mapping for ZT micro-perimeters; third-party and supply chain ZT considerations
›Building ZT policy — Kipling Method: who, what, when, where, why, how for each transaction; policy engine inputs: identity, device, location, time, risk score; dynamic vs. static policy
›ZT organizational change management — ZT champions; training users and administrators on ZT principles; phased rollout to minimize operational disruption; metrics for ZT maturity progress
Module 04
Zero Trust in Networks
›Micro-segmentation design — logical segmentation of workloads regardless of physical location; host-based (agent), network-based (switch/SDN), and hypervisor-based (VM) micro-segmentation approaches; segment policy design
›Software-Defined Perimeter (SDP) — SDP architecture: Controller, Gateway, Client; SDP vs. VPN: per-app access vs. full-tunnel; single-packet authorization (SPA); SDP for contractor and third-party access
›SASE (Secure Access Service Edge) — SASE components: SD-WAN + SSE (ZTNA, CASB, SWG, FWaaS); SASE vs. traditional hub-and-spoke; SASE deployment for branch, mobile, and cloud workloads
›SD-WAN integration with ZT — SD-WAN segmentation for ZT; application-aware routing; SD-WAN + ZTNA for remote branch ZT; integration with SASE fabric
›Network Access Control (NAC) — NAC for device compliance enforcement at network edge; 802.1X authentication; quarantine VLAN for non-compliant devices; NAC integration with identity (LDAP/AD)
›East-west traffic inspection — internal network ZT for lateral movement prevention; service mesh for application traffic; DNS-based ZT filtering; encrypted east-west traffic decryption for inspection
Module 05
Identity-Based Zero Trust
›Identity and Access Management (IAM) design for ZT — IAM architecture: IdP, federation, SSO; SAML 2.0, OAuth 2.0, OIDC protocols; attribute-based access control (ABAC) for ZT policy evaluation
›Multi-Factor Authentication (MFA) design — MFA factors: knowledge, possession, inherence; phishing-resistant MFA: FIDO2/WebAuthn hardware tokens; MFA for privileged users vs. standard users; step-up authentication triggers
›Privileged Access Management (PAM) — PAM for ZT: just-in-time (JIT) privileged access; session recording and monitoring; privileged access workstations (PAWs); PAM integration with SIEM for anomaly detection
›Public Key Infrastructure (PKI) for ZT — PKI role in ZT: mutual TLS (mTLS) for service-to-service authentication; certificate lifecycle management; OCSP and CRL for certificate revocation; HSM for CA key protection
›User and Entity Behavior Analytics (UEBA) — UEBA for continuous verification: baseline behavior modeling, anomaly detection; UEBA risk scoring as ZT policy input; insider threat detection patterns
›Device trust in identity-based ZT — device certificate-based authentication; hybrid Azure AD join for Windows; managed vs. unmanaged device policies; conditional access policies combining identity + device health
Module 06
Zero Trust Monitoring and Maintenance
›SIEM for ZT — SIEM role in ZT: centralized log aggregation from identity, endpoint, network, application, data sources; correlation rules for ZT violations; SIEM-driven ZT policy feedback loop
›XDR (Extended Detection and Response) — XDR architecture: cross-domain telemetry correlation; ZT use case: detecting lateral movement attempts; XDR + SOAR for automated response
›SOAR (Security Orchestration, Automation, and Response) — SOAR playbooks for ZT incident response: automatic session revocation on anomaly; device quarantine on malware detection; ZT policy update based on threat intelligence
›Policy automation for ZT maintenance — automated ZT policy review cycles; policy drift detection; zero-touch policy updates from threat intelligence feeds; ZT policy testing in staging before production
›ZT governance and metrics — ZT KPIs: number of verified access requests, policy enforcement coverage, MFA adoption rate, mean time to detect/respond; ZT maturity reassessment cadence; CISA maturity model annual review
Technologies You Will Master
Zero Trust
NIST SP 800-207
CISA ZT Model
SASE/SDP
Micro-Segmentation
IAM/PAM
MFA/FIDO2
UEBA Analytics
SIEM/XDR
SOAR Automation
PKI/mTLS
SD-WAN + ZT
Conditional Access
Device Trust
DLP/IRM
ZT Policy Engine
Zero Trust
NIST SP 800-207
CISA ZT Model
SASE/SDP
Micro-Segmentation
IAM/PAM
MFA/FIDO2
UEBA Analytics
SIEM/XDR
SOAR Automation
PKI/mTLS
SD-WAN + ZT
Conditional Access
Device Trust
DLP/IRM
ZT Policy Engine
Full Curriculum
6-Module D-ZT-DS-23 Programme
›History: perimeter failure vs ZT philosophy; NIST SP 800-207 definition
›Core tenets: never trust, always verify; least privilege; assume breach
›ZT business drivers: cloud, remote work, BYOD, API integrations
›CISA ZT Maturity Model stages: Traditional → Initial → Advanced → Optimal
Earn the D-ZT-DS-23 Dell Proven Professional certification and validate your expertise in designing and implementing Zero Trust security strategies for enterprise environments.