Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
The federal zero-trust strategy memorandum: specific end states across identity, devices, networks, applications and data, with dates attached and an agency implementation plan required against them.
What This Framework Contributes.
The memorandum states end states; this framework states whether you are positioned to reach them. It produces no implementation plan and meets no deadline.
- A measurement for each end state rather than a status. Phishing-resistant authentication is a rung on a sub-tower ladder with an observable attached, not a yes/no field.
- The same five goal areas as terrain, so progress against the memorandum and defensive position are read off one map instead of two.
- Forms of maneuver that have to be traceable to one of the memorandum’s end states or they are decoration — which is a constraint on the catalog, not a claim about the agency.
What it does not do for OMB M-22-09.
Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of OMB M-22-09 will be wrong in a way that is expensive to discover later.
- The agency implementation plan and budget submission.Both are agency documents on the memorandum’s own schedule. Nothing here produces either, and the framework’s cadence is not the memorandum’s.
- The deadlines.The memorandum carries dates. This framework carries thresholds. A threshold met says nothing about a date met, and an agency reading the two together should keep them apart.
- Enterprise procurement.Several end states are reached by buying and deploying something estate-wide. The framework can say where the gap is and what it costs positionally; it cannot close it.
5 elements, each with what is missing.
OMB M-22-09 publishes no control-level index for a catalog to be turned round against, so these edges are authored rather than derived. Each one is stated as a citation and resolved against the real catalog when the site is built: the prose can go stale, the links cannot go dead.
Identity
4 controls · T1 IdentityAgency staff use enterprise-managed identities to access the applications they use in their work, and phishing-resistant multifactor authentication protects them from sophisticated online attacks.
Phishing-resistant authentication is a rung on a sub-tower ladder with an observable attached, and the policy decision point that enforces it is designated as key terrain with a protection floor.
The memorandum requires an enterprise identity system and a plan to reach it. The framework measures the position; it does not procure, deploy or plan the migration.
Devices
4 controls · T2 DevicesThe agency maintains a complete inventory of every device it operates and authorizes for government use, and can prevent, detect and respond to incidents on those devices.
Managed and unmanaged devices are scored as different ground rather than averaged together, and terrain currency is what stops the inventory being complete only on the day it was built.
Endpoint detection deployment, and the visibility the memorandum asks agencies to give CISA, are outside the framework entirely.
Networks
4 controls · T3 NetworksAgencies encrypt DNS and HTTP traffic, and work toward breaking down perimeters into isolated environments.
Segmentation is assigned to specific ground and tracked to an implementation state, and barrier sufficiency asks the question that matters — whether the segment actually stops the movement it was built to stop.
Encryption of DNS and HTTP traffic is an engineering program with a deadline. The framework can say what is exposed and what it costs positionally; it cannot deliver the encryption.
Applications and workloads
4 controls · T4 Applications and WorkloadsAgencies treat all applications as internet-connected, routinely subject them to rigorous empirical testing, and welcome external vulnerability reports.
Reachability assessment is empirical testing aimed at the question the memorandum is really asking — whether the application can be reached from outside the assumption that protects it.
A vulnerability disclosure policy, an external reporting channel and the requirement to expose an internal application to the public internet are all agency actions the framework neither performs nor tracks.
Data
4 controls · T5 DataAgencies are on a clear, shared path to deploy protections that make use of thorough data categorization, and take advantage of cloud security services to monitor access to their sensitive data.
Data is weighted rather than merely classified, and privacy and controlled-unclassified holdings are put on the map as terrain with an authority attached rather than tracked as a register.
Enterprise data categorization, logging maturity against the logging memorandum, and the cloud monitoring services themselves are outside the framework’s scope.
Authored edges, derived resolution. Each goal area cites a terrain layer and control ids; the sub-towers, their maturity ladders and the controls are read from the terrain reference and the catalog. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.