Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Zero trust architecture (ZTA)

Also known as: ZTA, Zero trust

German: Zero-Trust-Architektur

In cybersecurity, a zero trust architecture (ZTA) is an enterprise security design in which no user, device or network location is trusted implicitly; every access request to a resource is authenticated, authorized and evaluated per session based on identity, device state and policy. NIST SP 800-207 describes its principles and components.

  • OT security
  • Standards

In one sentence

A zero trust architecture trusts no user, device or network location by default and checks every access request per session against identity and policy.

Example

Instead of granting access to the whole engineering network once a VPN is up, the zero trust gateway allows an engineer to reach only the one controller named in the approved work order.

How it applies

  • Engineering: Core components in NIST SP 800-207 are a policy decision point, which decides on access, and policy enforcement points, which grant or block it. Access is granted per resource and session, not per network segment.
  • Operation: Zero trust shifts the focus from the network perimeter to identities and resources. It relies on strong authentication, device health information and fine-grained policies, all of which need to be maintained.
  • Planning: Zero trust is a set of principles and a migration path, not a product. Vendor claims that a single tool delivers zero trust should be examined critically.
  • Documentation: Architecture documents should describe policy decision and enforcement points, the policies and their owners. Product documentation should state which identity and authentication mechanisms a component supports, since that determines whether it can take part.

Zero trust vs. perimeter security

Perimeter security trusts everything inside the network boundary. Zero trust assumes an attacker may already be inside and checks every access. In OT, both are often combined; see Zero trust in industry.

By knowledge.aitechdoc.world · Published September 28, 2026 · Last reviewed

Source: NIST SP 800-207:2020, Zero Trust Architecture

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!