“Zero trust” still confuses people—and for good reason. While the term conveys a certain absolute authority (“zero,” “nope,” “nothing”), contemporary approaches offer much more nuanced capabilities. And while zero trust today is typically associated with security initiatives, the concepts have their origin in the definition of network perimeters, who is granted access, and how that access is provided.
The evolution of security hasn’t been from implicit trust to no trust, but rather toward contextual controls that grant the right people the right access to the right resources at the right time for the right reasons. But ultimately, making sense of zero trust requires an understanding of how the role of networking and infrastructure has shifted with respect to the critical objectives of security in recent years.
The changing role of the network: a brief history
In the earliest days of building networks and defining the enterprise perimeter, all companies were essentially islands. They built corporate networks to facilitate interactions between employees and data that was all on-premises. When the internet came along, everyone wanted to get in on that. But businesses realized fairly quickly that the internet’s default implicit trust was going to cause problems when it came to protecting themselves from outsiders with malicious intent.
The first natural step was to use the network to create demarcation points. Architectures evolved to include something called a DMZ, which has a similar function as physical-world demilitarized zones (such as the 2.5-mile wide strip of land between North Korea and South Korea; the natural isolation of which created an involuntary park now regarded as one of the most well-preserved areas of temperate habitat in the world). This kind of “castle and moat” architecture actually worked for a long time. But then as businesses evolved and required constant connectivity with other busi