Active Draft standard
Most Recent

IEEE P3409

IEEE Draft Standard for a Zero Trust Security

Summary

New IEEE Standard - Active - Draft.
This draft standard for Zero Trust Security provides a comprehensive framework for implementing Zero Trust Architecture (ZTA), a cybersecurity paradigm that emphasizes the principles of "never trust, always verify," assume breach, and apply least privilege. The standard outlines requirements for transitioning from traditional perimeter-based security models to dynamic, granular security controls that protect organizational assets. The framework is structured around five core domains--Identity, Devices, Networks, Applications & Workloads, and Data--and three cross-cutting domains--Governance, Visibility & Analytics, and Automation & Orchestration. It offers guidance on aligning security policies, implementing continuous monitoring, automating security actions, and safeguarding sensitive data. Designed for developers, architects, and governance stakeholders, this standard aims to mitigate risks, enhance compliance, and adapt to the evolving threat landscape. It emphasizes incremental implementation, organizational change management, and leadership oversight to ensure the successful adoption of Zero Trust principles.

This standard provides a framework for zero trust security, including terminology, concepts, and identification of core elements.
This standard is intended to help developers and architects as well as other standards organizations identify the key security elements and considerations when implementing zero trust solutions. Additionally, it helps identify security priorities when transitioning from perimeter-based security models to zero trust-based models.

Notes

Active

Technical characteristics

Publisher Institute of Electrical and Electronics Engineers (IEEE)
Publication Date 09/02/2026
Page Count 33
EAN ---
ISBN ---
Weight (in grams) ---
No products.

Previous versions

No products.