ISC study / Cybersecurity

Zero Trust: Evaluate the Request, Not Just the Network

Quick answer

Zero trust grants no implicit trust just because a device is company-owned or inside the office network. Evaluate the identity, device state and requested resource under policy, then reevaluate access as relevant conditions change.

Reviewed . Original CPAPass exercises.

A vendor bank export request is evaluated using identity, device health and resource policy. The access path enforces the result and returns new signals for reevaluation.

1. Find the implicit-trust assumption

An internal network address is context, not automatic permission. A remote request can qualify, while an internal request can fail.

Least privilege limits access to what is needed. Zero trust also rejects a trusted perimeter as sufficient grounds for access.

Under the example policy, a company laptop in the office fails with unhealthy status; a healthy remote device passes when identity and export permission also pass.

2. Apply an original access-policy example

Lena is authorized to export vendor bank details. Assume the company permits that export only with verified identity, approved export permission and a currently healthy device.

Policy elementRequirement
ResourceVendor bank export
IdentityVerified
PermissionExport approved
DeviceCurrently healthy

Her company laptop is on the office network but fails the device-health check. Deny the export under this policy; ownership cannot replace the missing condition.

Quick check: Lena later connects remotely with all three conditions satisfied. Must access fail because she is outside the office?

Check the remote request

No. The stated conditions pass. Remote location alone does not disqualify the request.

3. Follow the decision through the session

A policy decision must be enforced on the access path. Allowing a session also requires monitoring; admission is not permanent trust.

Assume a later device alert changes its status to quarantined. The example policy requires suspension. Reevaluate and enforce that result even though the user has not moved.

NIST separates the policy engine, which decides, from the policy administrator, which establishes or tears down the path, and the policy enforcement point, which enables, monitors or terminates the connection. A decision recorded in a log is insufficient if the path still permits the prohibited action.

Access to the export service does not automatically grant access to another resource.

The session starts with passing conditions. A later quarantine signal triggers reevaluation and suspension under the example policy.

4. Avoid the common shortcuts

MFA helps authenticate an identity; it does not alone establish a zero-trust architecture.

Continuous evaluation does not mean entering another code for every click. Signals and policy determine when reauthentication or a new decision is needed.

Zero trust is an architectural approach, not one product or a guarantee against every breach.

5. Try a changing-session question

An analyst passes MFA and opens an approved resource from a company laptop. During the session, the device becomes quarantined. The stated policy suspends access for quarantined devices. Which response follows zero-trust principles?

  • A. Keep access because the device belongs to the company.
  • B. Reevaluate and suspend access under the stated policy.
  • C. Keep access until the employee leaves the office.
  • D. Grant access to other resources because MFA succeeded.
Reveal the answer and explanations

B is correct. Reevaluate the changed device state and enforce suspension under this policy.

  • A substitutes ownership for current evidence.
  • C makes office location the deciding factor.
  • D incorrectly extends one successful authentication to other resources.

Check your reasoning

  1. Identify the requested resource.
  2. Apply current signals to its policy.
  3. Reevaluate relevant changes.

Common zero trust questions

Does zero trust mean denying every request?

No. Permit requests that satisfy the applicable policy.

Is a corporate VPN enough?

Network location alone does not establish trust.

Is device ownership irrelevant?

It can inform policy, but cannot by itself establish trust.

Must every click trigger MFA?

No. Reauthentication follows policy and relevant signals.

Related ISC study

Scope and sources

The January 2026 ISC Blueprint expressly includes defining zero-trust. NIST SP 800-207 (August 2020) supports the principles. These original scenarios use an assumed company policy, not a universal device rule. They illustrate the topic without implying exam frequency, AICPA authorship or endorsement.