Skip to content

Zero Trust

Zero Trust seeks to minimise implicit trust through approaches such as continuous verification, least privilege and segmentation.

ORSM does not challenge those objectives. It evaluates whether their implementation remains operationally sustainable.

Questions include:

  • What happens if the identity or policy decision service is unavailable?
  • Can administrators recover systems when normal trust services have failed?
  • Has micro-segmentation created recovery dependencies?
  • Is policy administration sustainable at enterprise scale?
  • Are exception volumes increasing?
  • Can the environment operate safely in a defined degraded mode?

A Zero Trust architecture can reduce security risk while simultaneously increasing operational fragility if these questions are not considered.