NSA Releases Zero Trust Guidance for Applications and Workloads
2025-02-01

The National Security Agency (NSA) has released new guidance on advancing Zero Trust maturity, focusing on application and workload security. This practical guide offers recommendations for Department of Defense, Defense Industrial Base, and other organizations, emphasizing progressive capabilities within a Zero Trust framework. Key areas covered include application inventory, cybersecurity supply chain risk management (C-SCRM), CI/CD and DevSecOps, automated risk-based authorization, and continuous monitoring. The NSA advocates for implementing principles like least privilege, micro-segmentation, continuous monitoring, and logging to protect applications and workloads from sophisticated cyber threats.
Tech