Enterprise Zero Trust — integrated architecture reference

archimatev1

/01 Views

Identity and access capability decompositionarchimate
Device and endpoint capability decompositionarchimate
Network and environments capability decompositionarchimate
Application and workload capability decompositionarchimate
Information protection capability decompositionarchimate
Visibility and analytics capability decompositionarchimate
Automation and orchestration capability decompositionarchimate
Governance and risk capability decompositionarchimate
Enterprise capability taxonomyarchimate
Strategic trace: Continuous verification of enterprise trust to Protect high-value business resourcesarchimate
Strategic trace: Protect high-value business resources to Enterprise Zero Trustarchimate
Strategic trace: Explicit context-aware authorization to Automation and orchestrationarchimate
Strategic trace: No implicit trust by network location to Network and environmentsarchimate
Strategic trace: Assessed decision effectiveness to Reduced unauthorized resource usearchimate
Strategic trace: Identity lifecycle to Explicit context-aware authorizationarchimate
Strategic trace: Protect high-value business resources to Least-privilege enforcementarchimate
Access lifecycle operational activity flowarchimate
Protected information usage operational activity flowarchimate
Assurance and response operational activity flowarchimate
Validate subject identity fulfills Identity and accessarchimate
Evaluate context and policy fulfills Automation and orchestrationarchimate
Resolve data classification fulfills Information protectionarchimate
Enforce rights or mask response fulfills Information protectionarchimate
Ingest control telemetry fulfills Visibility and analyticsarchimate
Coordinate incident remediation fulfills Automation and orchestrationarchimate
Identity services logical servicesarchimate
Policy control services logical servicesarchimate
Security operations services logical servicesarchimate
Access management systems system interactionsarchimate
Resource enforcement systems system interactionsarchimate
Security operations systems system interactionsarchimate
System realizes Identity verification servicearchimate
System realizes Session assurance servicearchimate
System realizes Policy evaluation servicearchimate
System realizes Policy administration servicearchimate
System realizes Decision distribution servicearchimate
System realizes Decision distribution servicearchimate
System realizes Telemetry collection servicearchimate
System realizes Threat analytics servicearchimate
System realizes Remediation coordination servicearchimate
System realizes Evidence reporting servicearchimate
Control-to-protected-resource realizationarchimate
Control-to-protected-resource realizationarchimate
Control-to-protected-resource realizationarchimate
Control-to-protected-resource realizationarchimate
Control-to-protected-resource realizationarchimate
Control-to-protected-resource realizationarchimate
Control-to-protected-resource realizationarchimate
Control-to-protected-resource realizationarchimate
Policy-to-system constraintarchimate
Policy-to-system constraintarchimate
Policy-to-system constraintarchimate
Policy-to-system constraintarchimate
Workforce or external user → Session brokerarchimate
Non-person principal → Session brokerarchimate
Policy decision engine → Application enforcement gatewayarchimate
Application enforcement gateway → Protected business applicationarchimate
Data protection agent → Classified enterprise informationarchimate
Telemetry pipeline → Security decision evidencearchimate
Policy decision engine → Versioned policy recordsarchimate
Assurance record keeper → Security decision evidencearchimate
Transition states and implementation incrementsarchimate
Information and service owner ownership and assurancearchimate
Security platform operator ownership and assurancearchimate
Data access and usage enforcement ownership and assurancearchimate
Authentication assertion endpoint interface and exchangearchimate
Policy context evaluation endpoint interface and exchangearchimate
Enforcement decision endpoint interface and exchangearchimate
Security telemetry intake endpoint interface and exchangearchimate
Policy permits bounded accessarchimate
Policy denies accessarchimate
Policy demands additional proofarchimate
Establish permitted sessionarchimate
Request remediation after denialarchimate
Step-up authentication challengearchimate
Reevaluate supplied identity evidencearchimate
Retry contextual decisionarchimate
Revoke active access on material context changearchimate
Cut off resource operationsarchimate
Audit revocation outcomearchimate

/02 About

Integrated vendor-neutral Zero Trust reference architecture spanning strategy, capability hierarchy, operational activities, logical interface contracts, systems, protection controls, adaptive decisions and evolution.

One shared semantic architecture for vendor-neutral Zero Trust. Separate views represent strategic outcomes, a multi-level capability taxonomy, operational activities, service families, system interactions, policy constraints, control realization and incremental transformation. Its architecture elements are single graph identities shared by every view within this package. The reference is a conceptual design baseline, not an official or certified security implementation. Consumers should refine interface contracts, approval/deny and remediation branches, runtime boundaries, threat assumptions, maturity evidence and risk ownership before production adaptation. Extended logical service exchanges: authentication assertions, policy-context evaluation, enforcement decisions and security telemetry have explicit consumer-interface-schema-provider models. Conditional access includes permit, deny, step-up, revocation and remediation outcomes, with explicit state transitions. Fail-closed behavior, timeouts, retry safety and information-specific obligations must be refined by the adopting enterprise.

Published by Lattix · 134 elements · 146 relationships · validated on publish

/03 Contents

Capability
Enterprise Zero Trust, Identity and access, Identity lifecycle, Strong authentication, Continuous session verification, Privilege governance, Device and endpoint, Device inventory, Compliance posture, Device attestation, Continuous remediation, Network and environments, Transaction flow discovery, Logical segmentation, Secure application access, Network policy automation, Application and workload, Service identity, API authorization, Workload isolation, Software supply-chain assurance, Information protection, Data classification, Cryptographic data protection, Data-rights enforcement, Data loss prevention, Visibility and analytics, Distributed telemetry, Identity and entity analytics, Threat correlation, Continuous control monitoring, Automation and orchestration, Policy administration, Policy decisioning, Policy distribution, Adaptive response, Governance and risk, Strategic Zero Trust direction, Security policy governance, Architecture assurance, Capability maturity management
Goal
Continuous verification of enterprise trust, Protect high-value business resources
Requirement
Explicit context-aware authorization
Principle
No implicit trust by network location
Outcome
Reduced unauthorized resource use
Measure
Assessed decision effectiveness
Control Objective
Least-privilege enforcement
Risk
Unauthorized information disclosure
Activity
Receive access request, Validate subject identity, Evaluate context and policy, Authorize or reject session, Discover protected resource, Resolve data classification, Enforce rights or mask response, Record information usage, Ingest control telemetry, Correlate risk and anomalies, Trigger policy reassessment, Coordinate incident remediation, Request posture or risk remediation, Collect additional proof, Re-evaluate context after proof, Terminate access and invalidate token, Record decision and obligations
Application Service
Identity verification service, Authenticator service, Session assurance service, Entitlement service, Policy evaluation service, Policy administration service, Policy context service, Decision distribution service, Telemetry collection service, Threat analytics service, Remediation coordination service, Evidence reporting service
Application Component
Identity authority, Session broker, Policy decision engine, Policy administration plane, Application enforcement gateway, Workload policy agent, Data protection agent, Network policy gateway, Telemetry pipeline, Detection and analytics engine, Automation coordinator, Assurance record keeper
Business Actor
Workforce or external user, Non-person principal
Role
Information and service owner, Security platform operator
Application
Protected business application, Security monitoring console
Data Store
Classified enterprise information, Security decision evidence, Versioned policy records, Cryptographic key custody
Device
Managed endpoint
Network
Segmented resource network
Control
Identity assurance, Device posture enforcement, Resource network isolation, Data access and usage enforcement, Cryptographic key controls, Evidence integrity protection, Policy change governance, Detection and monitoring
Policy
Adaptive access policy, Endpoint compliance policy, Network segmentation policy, Data handling and classification policy
Plateau
Current-state baseline, Identity and asset foundation, Distributed resource controls, Continuous adaptive security
Work Package
Inventory resources and flows, Introduce contextual identity, Distribute policy enforcement, Automate response and assurance
API
Authentication assertion endpoint, Policy context evaluation endpoint, Enforcement decision endpoint, Security telemetry intake endpoint
Message/Event Schema
Identity assurance assertion, Subject resource action and environment claims, Permit deny step-up revoke obligation, Correlated security event and timestamp
State
Permit: bounded session, Deny: no resource admission, Step-up: stronger identity proof required, Revoke: terminate active access