Zero Trust Network Access
Also known as:ZTNA
Zero Trust Network AccessNetwork AccessThe ability of a user, device, or workload to connect to and use network resources.: Grants application-specific remote access based on identity, device state, and context. Controls apply to network communicationNetwork CommunicationThe exchange of data between systems over network protocols and connections. or network access points. Effectiveness is achieved through restrictive rules, segmentation, continuous monitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes., and coordinated response processesResponse ProcessA coordinated sequence of decisions and actions for handling security events and incidents..
How it works and where it fits
Zero Trust Network Access concerns communication between systems and therefore addressing, protocol state, trust boundaries, and reachable services. Security analysis must look beyond individual packets to direction, session, identity, encryption, and intended purpose. Different network layers introduce their own controls, assumptions, and failure modes.
Practical security relevance
Communication paths should be documented, unnecessary connections prevented, and permitted flows defined as narrowly as practical. Segmentation, secure protocols, authentication, and logging reinforce one another. Monitoring should cover known signatures as well as unusual destinations, volumes, and timing; rule and topology changes belong in a controlled process.
Related concepts
- Zero TrustZero TrustSecurity model that grants no implicit trust and verifies every request based on context.: Security model that grants no implicit trust and verifies every request based on context.
- Network Access ControlNetwork Access ControlVerifies devices and users before granting network access.: Verifies devices and users before granting network access.
- Security Service EdgeSecurity Service EdgeCloud-delivered security functions for access, web traffic, and data control.: Cloud-delivered security functions for access, web traffic, and data control.
- Identity and Access ManagementIdentity and Access ManagementManages digital identities, roles, permissions, and access lifecycles.: Manages digital identities, roles, permissions, and access lifecycles.