We'll explore the core principles of zero trust as applied to real-world architectures & demonstrate how & where they can limit impact. We will perform case studies & show the delta between conventional & zero trust architectures. The purpose is to walk away with tangible, actionable items.DescriptionIntroduction (about the speaker and the topic)Why is zero trust needed? What is the current threat landscape?What is zero trust? History of zero trust, evolution over the years.Historical three tenets of zero trust and why they needed improvementModern approach to zero trust. Three core principles considered during zero trust implementation5 pillars of zero trust and the 4 zero trust maturity models per CISAZero trust framework and NIST-based architectural approachCase 1 of a real-world application without zero trustRecognizing business and technical requirementsIdentifying subjects and assets within the architectureApplying principles of zero trust to the given architectureCase 2 of a typical modern architectureRecognizing business and technical requirementsIdentifying subjects, assets, network boundaries, permissions, roles etc.Applying principles of zero trust for legitimate, just in time accessHow do we realistically implement zero trust into product environments?Further resources on zero trust and conclusion