Skip to content

OZTP Top 10 Zero Trust Controls

The problem with Zero Trust isn't the concept — it's the starting point.

NIST, CISA, and the NSA all agree: Zero Trust is the right model. But their frameworks are comprehensive by design, built for large agencies with mature security teams. For most organizations, reading them produces paralysis, not progress.

This list cuts through that. Ten controls, reorganized into a maturity-based progression: Foundational Hygiene, System Hardening, and Zero Trust Architecture.

How OZTP helps

Each entry notes our role honestly: where the Control Platform or Agent Zeta help directly, where we advise, and where we point the way to other solutions.

Phase 1: Foundational Hygiene

#1 — Require Multi-Factor Authentication on Everything

Identity · Immediate · Free to start What it stops: Credential theft, phishing, and password spray attacks. Where to start: Enable MFA on your email and identity provider today. Use any authenticator app—Microsoft Authenticator, Google Authenticator, or Authy. For higher assurance, use FIDO2/passkeys.

#2 — Know Every Device on Your Network

Devices · High impact · Low cost What it stops: Unmanaged or unauthorized devices accessing your systems. Where to start: Build a device inventory—spreadsheet first, tooling later. Devices not in inventory should be denied access by default.

#3 — Protect Admin Accounts Like the Crown Jewels

Identity · High impact · Practice and policy What it stops: Admin account compromise leading to complete network takeover. Where to start: Separate admin accounts from daily-use accounts. Never use a privileged account for email, web browsing, or routine work.

#4 — Encrypt What Matters, Everywhere It Lives

Data · High impact · Many free options What it stops: Data exfiltration even when attackers gain access to storage or intercept network traffic. Where to start: Enable BitLocker on Windows endpoints and ensure all web-facing services use HTTPS.


Phase 2: System Hardening

#5 — Control What Software Can Run

Devices + Applications · High impact · Built into Windows What it stops: Malware, ransomware, and unauthorized tools. Where to start: Windows Defender Application Control (WDAC) / App Control for Business is built into Windows 10/11 Pro and Enterprise. Start in audit mode.

#6 — Give Everyone the Minimum Access They Need

Identity + Applications · High impact · Policy and process What it stops: Lateral movement. Where to start: Audit user accounts and remove unnecessary admin privileges. Access should be granted for a specific resource, for a specific reason, for the minimum time required.

#7 — Log Everything. You Will Need It Later.

Visibility & Analytics · High impact · Low cost to start What it stops: Long dwell time; makes detection and investigation possible. Where to start: Centralize your logs. Free and open source SIEM options include Wazuh and OpenSearch.


Phase 3: Zero Trust Architecture

#8 — Divide Your Network

Networks · High impact · Moderate complexity What it stops: Lateral movement. Segmentation turns a breach foothold into a dead end. Where to start: Identify your most sensitive systems and isolate them on separate network segments. Even basic VLAN separation significantly reduces blast radius.

#9 — Replace "Connected = Trusted" with Identity-Based Access

Networks + Identity · High impact · Multi-phase journey What it stops: The implicit trust that VPNs create. Where to start: Inventory what your VPN is actually used for, application by application. Migrate to identity-based access (ZTNA) one application at a time.

#10 — Machines Have Identities Too. Secure Them.

Identity + Applications · Growing urgency · Often overlooked What it stops: Supply chain attacks, compromised automation, and API key theft. Where to start: Audit service accounts and API keys. Use tools like GitHub's secret scanning to find exposed credentials.


Framework Mapping

# Control Phase CISA ZTMM Pillar CIS Controls v8
1 Multi-Factor Authentication 1 Identity 6
2 Device Inventory & Health 1 Devices 1
3 Admin Account Separation 1 Identity 5
4 Encryption at Rest & in Transit 1 Data 3
5 Application Control 2 Devices + Applications 2
6 Least Privilege Access 2 Identity + Applications 5, 6
7 Logging & Continuous Monitoring 2 Visibility & Analytics 8, 13
8 Network Micro-segmentation 3 Networks 12
9 Identity-Based Network Access 3 Networks + Identity 12, 13
10 Non-Human Identity Security 3 Identity + Applications 5

Primary references: NIST SP 800-207, CISA ZTMM, CIS Controls v8, NSA Zero Trust Guidance, ISO/IEC 27001.

Primary references: NIST SP 800-207 · CISA ZTMM v2 · CIS Controls v8 · NSA Zero Trust Guidance · ISO/IEC 27001


Ask Agent Zeta

Not sure where your organization stands, or where to begin? Agent Zeta can assess your current posture, map your gaps to the controls above, and suggest a prioritized starting point.

Agent Zeta

AI Zero Trust Advisor · Ask anything about these controls

Where do we start? MFA on a budget Getting started with WDAC Common mistakes Assess my maturity Securing machine identities

Powered by OZTP · For informational use · Not a substitute for a security audit · Conversations may be stored