Part Two · Field Briefing No. 01

The Architecture

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) organizes Zero Trust adoption into five pillars, tied together by three capabilities that cut across all of them. Federal agencies were required to build a transition plan around this model following Executive Order 14028 and OMB memo M-22-09.

Section 01 — Five Pillars

What Gets Verified

Each pillar covers a category of "thing" that has to prove itself before it's trusted with access — none of them ranked above another; a mature Zero Trust program advances all five together.

Pillar

Identity

Confirming who or what is asking — continuously, and with strong signals like phishing-resistant multi-factor authentication rather than a password alone.

Pillar

Devices

Knowing the health and integrity of every device connecting in, from an employee's laptop to an unattended server, before it's trusted with a session.

Pillar

Networks

Segmenting traffic into small, encrypted zones instead of trusting something simply because it's "inside" — see Article IV, Microsegmentation.

Pillar

Applications & Workloads

Securing the software itself, including the pipelines that build and deploy it, with access checked at the application layer, not the network edge.

Pillar

Data

Classifying, tagging, and encrypting information so its protection travels with the data itself, wherever it ends up.

Section 02 — Cross-Cutting Capabilities

What Ties the Pillars Together

Three capabilities run underneath all five pillars rather than belonging to any one of them.

Visibility & Analytics

The telemetry and context that every access decision is actually based on — without it, "continuous verification" has nothing to verify against.

Automation & Orchestration

Turning policy into something enforced by systems in real time, rather than a document reviewed once a quarter.

Governance

The policies, roles, and risk decisions that define what "least privilege" and "verified" actually mean for a given organization.

Section 03 — Maturity Model

Four Stages, One Direction

CISA's Zero Trust Maturity Model scores each pillar along the same four stages. Most organizations don't sit at one stage across the board — a pillar can be Advanced while another is still Initial.

Stage 1

Traditional

Manual processes, static policies, and perimeter tools like firewalls and VPNs doing most of the work.

Stage 2

Initial

Early automation and risk-based decisions begin, with identity and access policy expanding past a simple password check.

Stage 3

Advanced

Centralized visibility and dynamic policy enforcement across most pillars, with coordination starting to happen between them.

Stage 4

Optimal

Fully automated, continuously verified access, with least privilege enforced in real time across every pillar at once.

Look Up a Term

Part Three collects the vocabulary from this briefing in one glossary, plus a short FAQ.

Open Resources