There are plenty of resources that explain what Zero Trust should be in theory.

In an earlier article, we walked through the three core principles that make up the "big idea" behind Zero Trust.

Principles are a fine place to start. They're a terrible place to stop. Knowing you should "assume breach" doesn't tell you a single thing about what to actually configure on Monday morning. Enter the seven tenets: the part of the Zero Trust Architecture that's specific enough to build against.


Quick Answer: NIST SP 800-207 defines seven tenets of Zero Trust: treat all resources as needing protection, secure all communication regardless of location, grant access per-session, use dynamic policy for every access decision, continuously monitor the integrity of all assets, enforce authentication and authorization dynamically every time, and collect telemetry to keep improving your posture. None of them will tell you which product to buy, but they will tell you what your architecture has to be able to do so.

That last part trips a lot of people up, so let's get into it. 


Where the 7 Tenets Actually Come From

If Zero Trust has an official rule book, it’s NIST SP 800-207. It’s the document everyone else (aka vendors, analysts, that one consultant with the slide deck) is quietly referencing, whether they cite it or not. Inside it are the seven tenets that describe what Zero Trust needs to look like once it leaves the whiteboard.

A quick note before the list: these tenets describe outcomes, not products. NIST isn’t telling you to buy a specific firewall or identity tool. It’s telling you what your environment needs to be capable of, and leaving the “how” up to you. That’s either liberating or mildly infuriating, depending on how much you enjoy vendor comparison spreadsheets.

Zero Trust Security Model (cropped 2)

The 7 Tenets of Zero Trust

1. All data sources and computing services are considered resources

Every data source and every computing service counts as a resource that needs protection. Laptops, SaaS apps, IoT devices, that forgotten VM someone spun up in 2021: if a user, device, or service touches it to do their job, it’s in scope. Zero Trust doesn’t grade on a curve for things that seem low-risk.

2. All communication is secured regardless of network location

Being “inside the network” earns you nothing anymore. Zero Trust starts from the assumption that a breach has already happened or is about to, so every connection gets the same level of scrutiny and encryption, whether it originates from the office, a coffee shop, or a partner’s network. The old idea of a trusted internal network and a hostile external one doesn’t hold up here.

3. Access to individual enterprise resources is granted per session

Access isn’t a standing privilege. It’s a per-session decision. A user or device gets verified, granted the minimum access needed for one specific resource, and that’s it. Need to touch a second resource? That requires its own verification.

4. Access is determined by dynamic policy

Static access rules age badly. Zero Trust calls for a policy that’s evaluated continuously and pulls in the widest reasonable set of signals, including:

  • Client or service identity, credentials, or behavior patterns
  • Device health, configuration, patch level, network location, and analytics.

If a device’s posture changes mid-session, like it suddenly looks compromised, the policy engine is supposed to notice and react, not wait for the next login.

5. The enterprise monitors and measures the integrity and security posture of all owned and associated assets

All devices connected to the organization’s IT infrastructure should be continuously monitored to ensure they remain configured in a state that is known to be legitimate and secure. Configuration files, system binaries, critical assets: if something changes without authorization, you need to know immediately, not during next quarter’s audit. File integrity monitoring exists specifically to answer this tenet.

6. All resource authentication and authorization are dynamic and strictly enforced before access is allowed

Access to resources is never ‘inherited’ from a previous step, no matter how recent. Policies are enforced every time a user, device, or service requests access to a resource. It’s repetitive by design. Never trust, always verify.

7. The enterprise collects as much information as possible on the current state of assets, network infrastructure, and communications, and uses it to improve its security posture

Zero Trust is meant to get smarter over time, not just stay locked in its initial configuration. That means collecting as much relevant information as possible on asset state, network traffic, access requirements, and then using it to refine policy, update allowlists, and close gaps you didn’t know existed until the data showed you.


Why These Tenets Deliberately Don’t Tell You What to Buy

Notice these tenets don’t name a specific tool or vendor category. That’s intentional, not an oversight. There isn’t one “correct” Zero Trust stack. There are many possible approaches to delivering an effective Zero Trust strategy. Each organization should develop a strategy and tool stack that matches its unique needs and existing infrastructure.

Stefan Lesaru, IDSA Zero Trust Technical Working Group Lead, and Big Data and Security Director at Atos, put it well:

“One of the biggest misconceptions is that Zero Trust is a tool or set of tools. It’s not. Each organization must define its own concept based on an evaluation of the current network environment and any gaps that exist. They have to embrace the concept and culture and then move towards it. Zero Trust is a journey that may take several years to realize, and each organization’s journey and final implementation will look different.”

The Tenet Most Zero Trust Strategies Quietly Skip

If you look back at the list, six of the seven tenets are essentially about access and authorization, aka who gets in, how often they’re checked, and under what conditions. This is where most of the security industry’s attention (and budget) goes.

Tenet 5 — continuously monitoring the integrity of your assets — tends to get a nod and then left behind. The problem is, access controls only protect the front door. They don’t tell you whether something inside your environment has already been tampered with or misconfigured. An attacker who’s already in, or an insider who already has legitimate access, walks right past your access policies. Integrity monitoring catches what happens next.


Zero Trust Frequently Asked Questions

Does NIST require specific products to achieve Zero Trust?

No. NIST SP 800-207 intentionally avoids prescribing specific tools or vendors. It defines required capabilities and outcomes, and leaves organizations to build a strategy that fits their own infrastructure


Are the 7 tenets of Zero Trust the same as the 3 principles?

No. The three principles describe the philosophy behind Zero Trust (assume breach, verify explicitly, enforce least privilege). The seven tenets, defined by NIST, get more specific about what an architecture built on that philosophy actually needs to do.

Where to Go From Here

The seven tenets are a solid blueprint, but blueprints have gaps. This one has a few that don’t get discussed nearly enough.

Our report, The Missing Components of Zero Trust, digs into what’s actually missing from most Zero Trust guidance, including:

  • The core principles and 7 tenets in full detail
  • How Zero Trust strategy and architecture eliminate implicit trust
  • Common Zero Trust mistakes and how to avoid them
  • A straight answer to: "Does Zero Trust actually work?"

 

Lauren Yacono is a marketing specialist at Cimcor with nearly five years of experience translating complex cybersecurity concepts into clear, actionable insights. Based in the Chicagoland area, Lauren holds a B.S. in Business Administration with a concentration in marketing from Indiana University. Over her time at Cimcor, she has developed deep familiarity with file integrity monitoring, regulatory compliance frameworks (including NERC CIP and PCI DSS), and the evolving threat landscape facing critical infrastructure and IT environments. Lauren is passionate about bridging the gap between technical security practices and business strategy, helping readers understand not just what to do to protect their digital environments, but why it matters.

September 03, 2026

Try CimTrak for Free

Get your Free 14-day trial of CimTrak

Just let us know what capabilities you want to test out, and we'll set up a trial in your environment.