Design a Zero Trust Architecture with identity-centric access, micro-segmentation, continuous verification, and device posture checks.
You are a Zero Trust security architect. Design a complete ZTA implementation for the following organization. ## Organization Profile - **Size**: [SIZE e.g. 200 employees / 5000 employees] - **Work Model**: [MODEL e.g. fully remote / hybrid / office-based] - **Cloud Environment**: [CLOUD e.g. multi-cloud AWS+Azure / single cloud / hybrid] - **Current State**: [CURRENT e.g. traditional perimeter / partial zero trust / VPN-based] - **Compliance**: [COMPLIANCE e.g. NIST 800-207 / CISA ZTA Maturity Model] ## Architecture Components ### 1. Identity Pillar - **Identity Provider**: [IDP e.g. Azure AD / Okta / Google Workspace] - Phishing-resistant MFA for all users (FIDO2/WebAuthn) - Conditional access policies based on risk signals - Privileged Access Management with JIT (Just-In-Time) elevation - Service identity with workload identity federation - Identity governance: access reviews, lifecycle management - SSO for all applications with SAML/OIDC ### 2. Device Pillar - Device registration and compliance checking - Endpoint Detection and Response (EDR) requirement - Device health attestation before resource access - BYOD vs managed device policies - Certificate-based device authentication - Continuous device posture assessment ### 3. Network Pillar - Micro-segmentation strategy per workload - Software-Defined Perimeter (SDP) / ZTNA replacement for VPN - DNS filtering and threat protection - Encrypted traffic inspection (TLS inspection) - East-west traffic monitoring - Network access based on identity, not location ### 4. Application Pillar - Application-level authentication and authorization - API gateway with identity-aware routing - Application proxy for legacy applications - Shadow IT discovery and governance - CASB for SaaS application control - WAF integration with identity context ### 5. Data Pillar - Data classification framework (public/internal/confidential/restricted) - Data Loss Prevention policies by classification - Encryption at rest and in transit everywhere - Rights management for sensitive documents - Data access logging and analytics - Cross-border data transfer controls ### 6. Visibility & Analytics - SIEM integration with all pillars - User and Entity Behavior Analytics (UEBA) - Risk scoring engine combining all signals - Automated response to high-risk events - Compliance dashboard and reporting - Maturity assessment against [COMPLIANCE] ## Implementation Roadmap - Phase 1 (0-3 months): Identity hardening and MFA rollout - Phase 2 (3-6 months): Device compliance and ZTNA deployment - Phase 3 (6-12 months): Micro-segmentation and data classification - Phase 4 (12-18 months): Full analytics and automation Generate the complete architecture document with diagrams, policy templates, and vendor-specific configurations.
Free to copy and use. Compatible with Claude 4 Opus, GPT-5, Gemini 2.5 Pro.
Assess your current security posture and set your target Zero Trust maturity level. Implement the roadmap phases sequentially. Measure progress against the CISA maturity model at each phase gate.
Initial release
Sign in and download this prompt to leave a review.