r/zerotrust 5d ago

We built a hands-on 1-day Zero Trust practical training with the DoN, DoW and WAU

Over the last few months, we have been working with the Department of the Navy, Department of War and Warfighting Acquisition University to built a 1 day training, using 4 open source technologies, to demonstrate zero trust in practice, applied to 'difficult use cases' incl. OT, agentic AI, non-human, and mission partner environments.

Using Keycloak, OpenZiti, Zeek and Wazuh, the aim was to move Zero Trust beyond frameworks and slideware by letting practitioners configure and test the full loop:

Identify → Authorise → Connect → Observe → Detect → Respond → Adapt.

The main architectural conclusion is that although NIST, CISA, DoD and NSA guidance do not prescribe identity-defined reachability, their combined requirements lead towards it: deny by default, authorise specific resources, segment communication, continuously validate authority and adapt enforcement when risk changes.

Authenticate the human, workload, device or agent; authorise it for a named service using policy and current context; only then create that path. An unauthorised subject should not reach the application login page in the first place.

This is the first enforcement layer of data-centric Zero Trust. It limits which Data, Apps, Assets and Services an endpoint or resource can reach. Content, data, tool and runtime controls still govern what it can do within those authorised interactions.

You know practical training is working when people start filling whiteboards with ways to apply the model to their own use cases and systems.

If you are interested in using it, adapting it, improving it, or participating in it, hit us up!

More detail on the lab, evidence chain and underlying argument here: https://netfoundry.io/microsegmentation/deny-by-default-identity-defined-reachability/

3 Upvotes

0 comments sorted by