惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
Microsoft Security Blog
Microsoft Security Blog
Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
D
DataBreaches.Net
U
Unit 42
P
Proofpoint News Feed
I
InfoQ
Apple Machine Learning Research
Apple Machine Learning Research
Google DeepMind News
Google DeepMind News
博客园 - Franky
博客园_首页
IT之家
IT之家
博客园 - 叶小钗
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
NSA Publishes New Zero Trust Implementation Guidelines
2026-02-02 · via www.infosecurity-magazine.com

A new set of Zero Trust Implementation Guidelines (ZIGs) detailing how organizations can progress to target-level zero trust maturity has been released by the US National Security Agency (NSA).

The guidance introduces Phase One and Phase Two of the ZIGs, designed to support the US Department of War's (DoW), previously the Department of Defense, zero trust framework and the wider US government cybersecurity strategy.

The newly published phases are intended to move organizations from the Discovery stage through to target-level implementation. They outline required activities, dependencies and outcomes while allowing flexibility for firms to tailor adoption based on operational needs and constraints.

Phase One establishes a secure baseline. It defines 36 activities that support 30 zero trust capabilities, helping organizations build or refine foundational controls before deeper integration. Phase Two builds on this work with 41 activities that enable 34 additional capabilities, focusing on integrating core zero trust solutions across component environments.

The phased approach reflects a modular design rather than a fixed roadmap.

Brian Soby, CTO and co-founder of AppOmni, said this structure reinforces the idea that zero trust is not a one-time deployment. "[It] is an operating model, not a product," Soby said, noting that policy decisions must be continuously evaluated and enforced as conditions change.

Read more on Zero Trust: Risk of AI Model Collapse to Drive Zero Trust Data Governance, Gartner Says 

Shifting From Perimeter Security to Continuous Evaluation

The guidance reinforces a shift away from perimeter-based security toward continuous authentication and authorisation of users, devices and applications. Zero trust operates on the principles of "never trust, always verify" and "assume breach," an approach increasingly viewed as necessary as cyber threats evolve.

Soby said one of the strongest aspects of the guidance is its focus on activity after authentication.

"Continuous evaluation has to happen after login, not just at login," he said. According to Soby, many successful attacks now occur post-authentication, where basic identity checks and device posture assessments offer limited protection without visibility into what happens inside applications.

The guidelines draw on several established frameworks developed under Executive Order 14028, including NIST Special Publication 800-207, the CISA Zero Trust Maturity Model Version 2.0 and the DoW Zero Trust Reference Architecture. The NSA developed the guidelines in close coordination with the DoW CIO to organize 152 Zero Trust activities into structured phases.

However, Soby warned that many organizations still misapply zero trust by focusing too heavily on network access controls alone. Treating zero trust network access as a complete solution overlooks how applications make and enforce their own access decisions.

"Any zero trust architecture that leaves visibility and management of the application policy decision points out of the architecture is expensive and grossly insufficient," he said.

The NSA said the current guidance is intended to help skilled practitioners achieve target-level zero trust maturity, with additional advanced phases potentially developed in the future.