Access control
What is your approach to zero-trust architecture?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
Adopt zero-trust principles: authenticate and authorize every request regardless of network location, verify device and user posture, and enforce least privilege continuously. Segment access and never treat the internal network as inherently trusted.What the security reviewer is checking
Because "zero trust" is heavily marketed, reviewers discount buzzwords and look for specific implemented principles: identity as the primary perimeter, per-request authentication and authorization, device posture checks, least-privilege segmentation, and the absence of a flat trusted internal network. A credible answer maps concrete practices to the model in NIST SP 800-207 rather than declaring "we are zero trust." It is perfectly acceptable — often stronger — to describe zero trust as a maturity journey and say which pillars are done and which are on the roadmap, since reviewers know full implementation is rare.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.Our security model follows zero-trust principles as described in NIST SP 800-207, treating identity — not network location — as the perimeter. Every request to internal applications and cloud infrastructure is authenticated through our identity provider with MFA and authorized per-session; there is no standing "inside the network equals trusted" zone, and we do not operate a traditional corporate VPN granting broad network access. Access to production requires short-lived credentials issued just-in-time and scoped to the task, with no permanent SSH keys or long-lived cloud access keys. Workloads are segmented so services communicate only over explicitly allowed, mutually authenticated paths, and device posture (disk encryption, EDR presence, OS version) is evaluated before corporate application access is granted. Remaining roadmap items, such as extending continuous posture re-evaluation to all legacy internal tools, are tracked in our security program with target dates.
Evidence reviewers expect you to attach
- Architecture overview or network diagram showing segmentation and access paths
- Access control policy describing least-privilege and just-in-time access
- Identity-aware proxy or IdP policy configuration summary
- Device management / posture policy (MDM or EDR requirements for access)
Follow-up questions reviewers ask next
- Is there any flat internal network segment where services trust each other by default?
- How is device health checked before granting access to corporate systems?
- Are production credentials long-lived or issued just-in-time?
- Is service-to-service traffic mutually authenticated (mTLS)?
- Which zero-trust capabilities are still on your roadmap?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated access control questions
Is multi-factor authentication (MFA) required for all users?What is your password policy?How do you handle employee offboarding?Do you perform background checks on employees?How do you manage access to production systems?Do you support single sign-on (SSO) for customers?
Browse the full security questionnaire question library