HomeSecurityNSA: New Zero Trust Implementation Guidelines (ZIGs)

NSA: New Zero Trust Implementation Guidelines (ZIGs)

The National Security Agency (NSA) has released a new, comprehensive set of Zero TrustImplementation Guidelines (ZIGs), attempting to transform the theory of Zero Trust into a practical, implementable cybersecurity model for organizations of all sizes. The guidelines aim to move from the initial design phase to achieving target-level zero trust maturity.

NSA Zero Trust

Zero Trust: Two phases for a structured transition

The new framework introduces Phase One and Phase Two of the ZIGs, which are designed to support both the U.S. Department of War’s (DoW) Zero Trust framework and the U.S. government’s overall cybersecurity strategy. This is an approach that aligns with the growing demands for protecting critical infrastructure and government information systems.

See also: How to set up a zero trust environment in your home

The two phases aim to move organizations from the “Discovery” stage—where assets, users, and data flows are mapped—to a fully operational zero-trust implementation, without imposing rigid timelines.

Phase One: Laying the Security Foundation

Phase One focuses on creating a secure baseline. It includes 36 distinct activities that support 30 core Zero Trust capabilities. The goal is for organizations to gain fundamental identity, access, and visibility controls before moving on to more complex integrations.

At this stage, the emphasis is on proper identity management, basic data classification , and establishing access policies that are no longer based on the user's physical or logical location.

Phase Two: Integration and operational maturity

Phase Two builds on the foundation of the first, adding 41 additional activities that enable 34 new Zero Trust capabilities. The focus shifts to solutions Zero Trust into real-world application, data, and endpoint environments.

NSA: New Zero Trust Implementation Guidelines (ZIGs)

At this stage, zero trust ceases to be a theoretical framework and becomes an operational model that influences daily application usage, access decisions, and ongoing risk monitoring.

See also: 15 years later, zero-trust is still not implemented

Zero Trust as an operating model, not as a product

The modular structure of the guidelines reflects a significant philosophical shift. As Brian Soby, CTO and co-founder of AppOmni, points out, zero trust is not a one-time technology installation.

“Zero Trust is an operating model, not a product,” he emphasizes, underlining that security policies must be constantly reevaluatedas threats, users, and business data change.

From perimeter defense to continuous assessment

Central to the new guidelines is the move away from traditional perimeter security in favor of continuous verification . The “ never trust, always verify ” philosophy reflects the modern reality, where attacks often originate from legitimate accounts.

Soby points out that many breaches occur after successful login, when authentication checks have already been completed. Without continuous assessment of activity within applications, even strong access control measures prove insufficient.

See also: Zscaler Acquires SPLX – Powering Zero Trust Exchange with AI

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

NSA: New Zero Trust Implementation Guidelines (ZIGs)

Common language with international standards

The NSA guidelines are based on established frameworks such as NIST SP 800-207, CISA’s Zero Trust Maturity Model (Version 2.0), and the DoW Zero Trust Reference Architecture. They were developed in close collaboration with the DoW CIO office, organizing a total of 152 Zero Trust activities into structured phases.

The pitfalls of incorrect implementation

Despite clear guidance, the NSA and independent experts warn that many organizations are still implementing the Zero Trust approach piecemeal, limiting it solely to the network layer. As Soby notes, such an approach ignores the critical role of applications.

The NSA concludes that the current guidelines are aimed at mature cybersecurity professionals, leaving open the possibility for future, even more advanced phases of Zero Trust.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS