Originally published on the Edilec blog: https://edilec.com/blog/sec-4108/zero-trust-for-business-applications/
Zero trust replaces implicit confidence based on network location with explicit, risk-informed decisions about each resource request. For a business application, that means authenticating people and workloads, authorizing the requested action on the specific resource, limiting session and credential scope, and using telemetry to reassess access. It does not mean distrusting employees as people, nor does it describe one product.
Define scope in business and risk terms
Bring together application owners, identity teams, endpoint operations, data stewards and support to map high-value resources and current access paths. Trace real requests from a person or workload through authentication, authorization and data access, including remote and partner scenarios.
Inventory protected resources, data sensitivity, users, workloads and existing access paths.










