The information sheet, titled Advancing Zero Trust Maturity Throughout the Network and Environment Pillar is aimed at empowering organisations to bolster their network security through the adoption of zero-trust framework principles.
In contrast to traditional IT security standards, which operate on the assumption of inherent trust within the network, zero-trust architecture operates on the premise that threats already exist and must be actively mitigated.
“Organisations need to operate with a mindset that threats exist within the boundaries of their systems,” said NSA cybersecurity director Rob Joyce. “This guidance is intended to arm network owners and operators with the processes they need to vigilantly resist, detect, and respond to threats that exploit weaknesses or gaps in their enterprise architecture.”
Central to the zero-trust model is the concept of gradual advancement through various components or pillars that threat actors may exploit during an attack. The NSA released guidance specifically targeting the network and environment component, encompassing hardware and software assets, non-person entities, and inter-communication protocols.
The zero-trust model encourages in-depth network security measures such as data flow mapping, macro, and micro segmentation, and software-defined networking (SDN). These strategies are designed to isolate critical resources from unauthorised access while enhancing visibility and control over network activities.
Data flow mapping involves identifying and monitoring the flow of data throughout the network. Advanced maturity in data flow mapping enables organisations to maintain comprehensive inventories and effectively mitigate potential security vulnerabilities.
Recommended reading
- Contributed | Implementing A Zero Trust Mindset
- Awingu Boosts Security with New Zero Trust Upgrade
- Data Protection Reforms Must Not Put UK and EU Data Flow at Risk
Macro segmentation allows organisations to compartmentalise network access based on user roles and departmental requirements, to minimise the risk of lateral movement by threat actors. Similarly, micro segmentation further reduces the attack surface by isolating users, applications, or workflows into individual network segments.
The integration of SDN components enhances network security by facilitating centralised control over packet routing and policy enforcement. This enables organisations to implement customised security measures while enhancing visibility and monitoring capabilities across the network.
The NSA’s guidance outlines four levels of maturity for each component within the network and environment pillar, ranging from initial preparation to advanced implementation of comprehensive security controls. The ultimate goal is to establish an enterprise architecture capable of resisting, identifying, and responding to emerging threats effectively.





