Join our Newsletter — 33% off our NHI Course

CISA zero trust maturity model: are your access controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: CISA’s Zero Trust Maturity Model translates Zero Trust Architecture into five operational pillars and three maturity stages, with identity, device, network, application workload, and data controls moving from manual to dynamic enforcement. StrongDM’s summary also cites a 15.1% rise in cyberattacks and data breaches in 2021, according to the article.

Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “CISA Zero Trust Maturity Model (TL;DR Version)”.

By the numbers:

  • In 2021, the average number of cyberattacks and data breaches increased by 15.1%.

Key questions

Q: What breaks when access governance still relies on standing entitlements in a zero trust model?

A: Standing entitlements break the logic of zero trust because they assume access can remain valid across changing risk conditions.

Q: Why does session-based access create risk in Zero Trust environments?

A: Session-based access creates risk because it assumes the first authentication decision remains valid for the entire session.

Q: How can security teams tell whether zero trust is actually working in AWS?

A: Look for evidence that access is issued for a narrow purpose, expires automatically, and is auditable across accounts and resource types.

Practitioner guidance

  • Map each pillar to a maturity stage Assess identity, device, network/environment, application workload, and data separately so you can see where static policy still dominates and where dynamic enforcement already exists.
  • Rebuild access reviews around runtime signals Stop treating recertification as the primary proof of control effectiveness when access is session-scoped and continuously revalidated.
  • Align PAM with zero standing privilege Remove standing access where possible and tie elevation to session context so privileged use remains auditable and narrow.

Bottom line: Zero trust maturity redefines access governance by making runtime verification more important than static entitlement ownership.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Zero trust changes access governance because it replaces entitlement permanence with session-bound verification. That is not just a tighter control posture, it is a different operating assumption for identity and privilege. Programmes built around periodic review and standing access have to reorient around continuous decision points, or they will keep certifying controls that the model has already made obsolete.

A few things that frame the scale:

  • 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Which matters more for zero trust maturity, authentication or authorisation?

A: Both matter, but authorisation becomes the decisive control once identity has been verified. Zero trust is not satisfied by strong login alone, because access must also be dynamically approved for the specific resource, session, and risk context. Mature programmes measure whether authentication outcomes are translated into tightly scoped, continuously enforced authorisation.

👉 Read our full editorial: CISA zero trust maturity model and what it means for access governance


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.