Does Zero Trust include network security?
Yes—network security is part of Zero Trust, but networks no longer define the security paradigm as in classic security approaches. Network security is a key part of security zones and other access control capabilities (alongside identity, application, data, and other technologies).
While network security once dominated security thinking and tooling, its role will be diminished to “one technology among many.” This is because the business assets to be protected are increasingly hosted on networks you don’t control, requiring the use of other technologies for effective security controls. Additionally, attackers are evading network-only protection strategies with phishing, credential theft, supply chain, and other attack techniques—adding to the requirement for other controls and technologies.
Figure 4.10 illustrates this dynamic:
Figure 4.10 – Limitations of network perimeter...