Cybersecurity GRC 17 items
Zero Trust Architecture Assessment (NIST 800-207)
Assesses maturity against the zero trust tenets and pillars defined in NIST SP 800-207 and the CISA Zero Trust Maturity Model.
NIST 800-207CISA ZTMMNIST 800-53
Free PDF · enter your email to download.
Zero Trust Tenets & Governance
- Has the organization defined protect surfaces and mapped transaction flows for critical resources? *
- Is access to resources granted per-session on a least-privilege basis? *
- Are access decisions made by a policy decision point evaluating dynamic signals? *
- Is a documented zero trust strategy and roadmap approved by leadership?
Identity Pillar
- Is every access request authenticated regardless of network location? *
- Is phishing-resistant MFA enforced for all users? *
- Are risk-based and continuous authentication signals evaluated at access time? *
Device Pillar
- Is device posture (patch level, EDR status, compliance) verified before granting access? *
- Is a real-time inventory of all assets accessing resources maintained? *
- Are non-compliant or unmanaged devices denied or quarantined? *
Network & Environment
- Is the network micro-segmented so lateral movement is restricted? *
- Is all traffic, including internal east-west, encrypted? *
- Are software-defined perimeters or identity-aware proxies used in place of implicit trust zones?
Application, Data & Visibility
- Are applications accessed through brokered, authenticated sessions rather than direct network exposure? *
- Is data classified and access governed by data-centric policies? *
- Are all access decisions and resource activity logged for analytics? *
- Is telemetry aggregated to continuously improve policy?
Download the full Zero Trust Architecture Assessment (NIST 800-207) checklist
Get it as a clean, printable PDF — free.
