A Survey on Zero Trust Architecture: Principles, Deployment, and Open Challenges
Abstract
Zero Trust Architecture (ZTA) is such a shift from traditional model of cybersecurity by focusing on a holistic approach rather than a perimeter-based security model. According to the authors' knowledge at the time a comprehensive overview of the ZTA concepts, deployment models, challenges, benefits, and future of it are discussed. The review article includes an insight on how ZTA can be used or applied for example in cloud networks, remote work sites, multicloud environments, and hybrid deployments with reference to NIST SP 800-207 guidelines and real-life settings. The article mainly discusses a survey of the literature covering NIST SP 800-207, industry guidance documents and other standards related to ZT. Besides, the paper highlights key challenges in adopting ZT that may hinder its widespread implementation. As one of the major findings from this paper shows, using a continuous verification mechanism as part of ZTA implementation can help reduce lateral movement incidents by as much as 72-90% and insider threats by 65%. In addition to this, the level of data protection should significantly increase. The review article is intended as a reference point for practitioners looking for a step-by-step guide on how to establish and deploy ZTA in cybersecurity systems.