Zero-trust access
securityv1/01 Views
/02 About
Every request is authenticated, authorized and checked against device posture by a policy engine before an access proxy lets it reach an application.
No request is trusted because of where it comes from. An access proxy in front of each application asks a policy engine to decide, using the user's identity, strong authentication, the device's posture and the access policy, and every decision is logged. When to use: remote and hybrid work, replacing network VPN access, protecting internal applications and administrative interfaces, and meeting least-privilege requirements. Trade-offs: much smaller blast radius and per-request control; it needs reliable identity, device inventory and well-maintained policies, and the policy path must be highly available.
Published by Lattix · 12 elements · 11 relationships · validated on publish
/03 Contents
- Business Actor
- Workforce user
- Device
- Managed device
- Application Component
- Access proxy, Policy engine, Device posture service
- Application
- Identity provider, Internal application
- Data Store
- Access decision log
- Policy
- Access policy
- Control
- Strong authentication, Least-privilege access, Continuous verification