Zero trust is a security model built on the idea 'never trust, always verify'. Older networks relied on a strong perimeter: once you were inside the office network or connected to the VPN, you were largely trusted. That fails when an attacker phishes one user and then moves freely inside. Zero trust removes implicit trust based on network location. Every request to access a resource is evaluated on its own, using identity, device health and context, and access is granted with least privilege for just that session. It matters because users, devices and data now live everywhere, in offices, homes and clouds, so 'inside' no longer means 'safe'.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 8 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.