# SP-029 Zero Trust Architecture

Status: active. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Enterprise security architecture pattern that eliminates implicit trust, enforcing continuous verification of every user, device, and workload before granting access to any resource. Maps 51 NIST 800-53 controls to the five zero trust pillars: identity, device, network, application, and data.
Use when: This pattern applies to any enterprise that has moved beyond the assumption that internal networks are safe. It is particularly relevant for organisations with significant remote or hybrid workforces, cloud-first or multi-cloud strategies, high-value data requiring granular access control, regulatory requirements for continuous monitoring and least privilege, a history of lateral movement in security incidents,...
Not when: This pattern may be premature for organisations that lack basic security hygiene: if you do not have centralised identity management, asset inventory, or patch management, zero trust adds complexity without a foundation to build on.

## Controls (51, NIST SP 800-53 ids)
- Critical (14): AC-01, AC-02, AC-03, AC-04, AC-06, AU-02, AU-06, CA-07, IA-02, IA-05, SC-07, SC-08, SC-32, SI-04
- Important (27): AC-05, AC-12, AC-17, AC-20, AC-21, AU-03, AU-09, AU-12, CA-02, CM-02, CM-05, CM-06, CM-08, IA-04, IA-08, IA-12, IR-04, IR-05, PL-02, PM-14, RA-03, RA-05, SA-08, SC-13, SC-23, SC-28, SI-07
- Standard (10): AC-07, AT-01, AT-02, AT-03, CM-03, IR-06, IR-08, MP-02, SC-39, SI-12

## What each critical control mitigates (14)
- AC-01 Policy and Procedures: none of the threats below
- AC-02 Account Management: T-ZTA-004
- AC-03 Access Enforcement: T-ZTA-001
- AC-04 Information Flow Enforcement: T-ZTA-001, T-ZTA-008
- AC-06 Least Privilege: T-ZTA-003, T-ZTA-004
- AU-02 Event Logging: T-ZTA-004
- AU-06 Audit Record Review, Analysis, and Reporting: T-ZTA-003, T-ZTA-008
- CA-07 Continuous Monitoring: T-ZTA-009
- IA-02 Identification and Authentication (Organizational Users): T-ZTA-002, T-ZTA-007
- IA-05 Authenticator Management: T-ZTA-002
- SC-07 Boundary Protection: T-ZTA-001, T-ZTA-009, T-ZTA-010, T-ZTA-011
- SC-08 Transmission Confidentiality and Integrity: T-ZTA-002, T-ZTA-005
- SC-32 System Partitioning: T-ZTA-001
- SI-04 System Monitoring: T-ZTA-003, T-ZTA-007, T-ZTA-008, T-ZTA-010, T-ZTA-012

## Threats and the controls that mitigate them (12)
- T-ZTA-001 Lateral movement after perimeter breach: SC-07, SC-32, AC-03, AC-04
- T-ZTA-002 Credential theft and replay attacks: IA-02, IA-05, SC-08, AC-12
- T-ZTA-003 Insider threat and compromised trusted user: SI-04, AU-06, AC-05, AC-06
- T-ZTA-004 Privilege escalation via over-provisioned access: AC-06, AC-02, CM-05, AU-02
- T-ZTA-005 Man-in-the-middle on internal network: SC-08, SC-13, SC-23, IA-08
- T-ZTA-006 Compromised endpoint accessing sensitive resources: CM-02, CM-06, SI-07, CM-08
- T-ZTA-007 Session hijacking and token theft: AC-12, IA-02, SC-23, SI-04
- T-ZTA-008 Data exfiltration through authorised channels: AC-04, AC-21, SI-04, AU-06
- T-ZTA-009 Trust engine poisoning via manipulated signals: SI-07, AU-09, CA-07, SC-07
- T-ZTA-010 Policy enforcement point bypass: CA-02, SA-08, SC-07, SI-04
- T-ZTA-011 Identity provider compromise: IA-04, IA-12, SC-07, IR-04
- T-ZTA-012 Shadow IT circumventing zero trust controls: CM-08, AC-20, SI-04, PM-14

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-029/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-029/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 29 KB: /api/v1/patterns/SP-029
- Page for people: /patterns/sp-029/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-001 Client Module; SP-002 Server Module; SP-010 Identity Management Pattern; SP-011 Cloud Computing Pattern; SP-016 DMZ Module; SP-025 Advanced Monitoring and Detection; SP-027 Secure LLM Usage; SP-028 Secure DevOps Pipeline

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
