The U.S. Department of Defense (DoD) released its zero-trust strategy and roadmap this week, aiming to achieve the department-wide implementation by fiscal year 2027. The release follows the White House’s push on zero trust that looks to move U.S. government agencies toward a zero-trust security approach.

In the release, the DoD refers to zero trust as a framework using security capabilities, including multi-factor authentication (MFA), micro-segmentation, advanced encryption, endpoint security, analytics, and robust auditing to fortify data, applications, assets, and services to deliver cyber resiliency.

The framework can reduce the attack surface, manage risks, and allow secure data-sharing for partnerships while ensuring adversary damage containment and remediation after a device, network, user, or credential is compromised, the department noted.

“Zero trust is much more than an IT solution. Zero trust may include certain products but is not a capability or device that may be bought,” DoD CIO John Sherman wrote in the report.

“The journey to zero trust requires all DoD Components to adopt and integrate zero-trust capabilities, technologies, solutions, and processes across their architectures, systems, and within their budget and execution plans,” he added. “Perhaps most importantly, they must also address zero-trust requirements within their staffing, training, and professional development processes as well.”

Security vendors applauded the DoD’s zero-trust strategy.

“The latest update provides crucial details for implementing the zero-trust strategy, including clear guidance for the DoD and its vendors regarding 45 separate capabilities and 152 total activities,” Microsoft Federal Security CTO Steve Faehl wrote in a blog post.

“The level of detail found in the DoD’s strategy provides a vendor-agnostic, common lens to evaluate the maturity of a variety of existing and planned implementations that were derived from the DoD’s unique insights into cyberspace operations,” Faehl added. “Furthermore, the DoD’s shift from a compliance and controls-based approach to an outcomes-focused methodology – meaning the job is done when the adversary stops, not just when the controls are in place – stands out as a best practice not seen elsewhere to this extent.”

PlainID CTO and CPO Gal Helemski echoed that statement, underlining the importance of zero-trust adoption. “Everyone must realize, the key to defending an organization from future cyberattacks is protecting the data and the applications, by ensuring that even if a bad actor – which can be a federal employee sometimes – has gained access credentials, they don't have automatic access to any or all data,” Helemski said. “Let's face it, zero trust is the only way to secure a modern, decentralized enterprise, in which data and applications are accessed from anywhere by employees, customers, and partners.”

DoD’s Four Zero-Trust Goals

In the report, the DoD outlined its four strategic goals to achieve its vision of zero-trust implementation for the next five years.

It plans to train all its personnel to be aware, understand, and commit to a zero-trust mindset and culture while supporting the integration into the security strategy. It will also incorporate and operationalize the zero-trust framework into its new and legacy systems.

Additionally, the DoD aims to deploy zero-trust technologies at least at an equal pace or even exceeding industry advancement. And it plans to make sure department- and component-level processes, policies, and funding are synchronized with its zero-trust principles and strategies.

The DoD added that zero-trust deployment is a continuous process and it will add more enhancement in the subsequent years as threats and technology evolve.