Access control

What is your approach to zero-trust architecture?

How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.

Expert answer

Adopt zero-trust principles: authenticate and authorize every request regardless of network location, verify device and user posture, and enforce least privilege continuously. Segment access and never treat the internal network as inherently trusted.

What the security reviewer is checking

Because "zero trust" is heavily marketed, reviewers discount buzzwords and look for specific implemented principles: identity as the primary perimeter, per-request authentication and authorization, device posture checks, least-privilege segmentation, and the absence of a flat trusted internal network. A credible answer maps concrete practices to the model in NIST SP 800-207 rather than declaring "we are zero trust." It is perfectly acceptable — often stronger — to describe zero trust as a maturity journey and say which pillars are done and which are on the roadmap, since reviewers know full implementation is rare.

Example response you can adapt

This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.
Our security model follows zero-trust principles as described in NIST SP 800-207, treating identity — not network location — as the perimeter. Every request to internal applications and cloud infrastructure is authenticated through our identity provider with MFA and authorized per-session; there is no standing "inside the network equals trusted" zone, and we do not operate a traditional corporate VPN granting broad network access. Access to production requires short-lived credentials issued just-in-time and scoped to the task, with no permanent SSH keys or long-lived cloud access keys. Workloads are segmented so services communicate only over explicitly allowed, mutually authenticated paths, and device posture (disk encryption, EDR presence, OS version) is evaluated before corporate application access is granted. Remaining roadmap items, such as extending continuous posture re-evaluation to all legacy internal tools, are tracked in our security program with target dates.

Evidence reviewers expect you to attach

  • Architecture overview or network diagram showing segmentation and access paths
  • Access control policy describing least-privilege and just-in-time access
  • Identity-aware proxy or IdP policy configuration summary
  • Device management / posture policy (MDM or EDR requirements for access)

Follow-up questions reviewers ask next

  • Is there any flat internal network segment where services trust each other by default?
  • How is device health checked before granting access to corporate systems?
  • Are production credentials long-lived or issued just-in-time?
  • Is service-to-service traffic mutually authenticated (mTLS)?
  • Which zero-trust capabilities are still on your roadmap?

Answer every security questionnaire in minutes

Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demo