Here is exactly how to deliver it.
Frequently Asked Questions
What are the five steps of the Zero Trust implementation process?
The five steps are: define the Protect Surface, map transaction flows, architect the environment, create the policy using the Kipling Method, and monitor and maintain.
What is the Kipling Method?
The Kipling Method structures every access policy around six questions: Who, What, When, Where, Why, and How.
Can one Zero Trust programme satisfy multiple compliance frameworks at once?
Yes. A single, properly structured Zero Trust programme can simultaneously satisfy ISO 27001, NIST 800-53, NIS2, DORA, PCI DSS, and several others, without running parallel compliance workstreams.
Why does Zero Trust matter specifically for hospitals?
When HVAC, water, or sterilisation systems are compromised in a hospital, it becomes a patient safety event, not just a business risk.
What is the Protect Surface, and why is it defined first?
The Protect Surface is an organisation's most critical data, assets, applications, and services (DAAS). It is smaller and more manageable than the full attack surface, which is why it is the first step of the five-step process.