The Cybersecurity and Infrastructure Security Agency (CISA) today released an updated version of its Zero Trust Maturity Model, which incorporates version 1.0 feedback from a public comment period and the latest government guidelines. The agency recommends all organizations review this guideline and continue their progress toward a zero-trust model.

CISA defines zero trust as “an approach where access to data, networks and infrastructure is kept to what is minimally required and the legitimacy of that access must be continuously verified,” based on the National Institute of Standards and Technology (NIST)’s definition.

Published in 2021, CISA’s model version 1.0 lists three stages to help organizations identify their zero-trust technology maturity: traditional, advanced and optimal. Version 2.0 adds an “initial” stage between traditional and advanced and includes revised criteria for all stages.

To reach the "initial" stage, agencies should move from the “traditional” stage's manual work to the automation of attribute assignment and configuration of lifecycles, policy decisions and enforcement. The addition is in response to requests for additional guidance and space to evolve along the maturity model.

The model also represents a gradient of implementation across five pillars — identity, devices, networks, data, and applications and workloads. Each pillar includes details regarding cross-cutting capabilities: visibility and analytics, automation and orchestration, and governance.

The "advanced" stage refers to cross-pillar coordination among applicable and automated controls for lifecycle and assignment of configurations and policies, along with centralized visibility and policy enforcement. Reaching the final "optimal" stage means an agency have fully automated, just-in-time lifecycles and assignments of attributes to assets and resources, as well as cross-pillar interoperability with continuous monitoring.

CISA tapped zero-trust comments

CISA claims the updated model is a result of comments gathered for version 1.0, a review of the Office of Management and Budget (OMB)’s Zero Trust Implementation Plans, input from CyberStat Working Groups, findings from National Security Telecommunications Advisory Committee (NSTAC) meetings, and one-on-one meetings with agencies, international partners and the greater IT community.

Along with the latest maturity model draft, the agency published the Response to Comments for Zero Trust Maturity Model, which summarizes version 1.0 comments gleaned during the 2021 public comment period. This includes 378 comments from agencies, vendors, consulting services, academic organizations, trade associations, individuals and foreign organizations.

Commenters also looked for updates to the longer-term zero-trust maturity model purpose and expanded content and guidance across all pillars and functions to provide more granularity to zero-trust architecture support implementation. CISA took that input to revise the latest text.

Although CISA has focused on providing zero-trust guidance to federal agencies, the model can also be beneficial to the private sector.

“As one of many roadmaps, the updated model will lead agencies through a methodical process and transition toward greater zero-trust maturity. While applicable to federal civilian agencies, all organizations will find this model beneficial to review and use to implement their own architecture,” CISA Technical Director for Cybersecurity Chris Butera said in a statement.