DHS, NSA creating reusable pieces to zero trust foundation – Federal News Network
An analysis by Bloomberg Government from last summer showed agencies have spent only $500,000 on zero trust architecture tools and services since fiscal 2017.
To be clear, that research only looked for specific mentions of what has become a buzzword mentioned at every conference and vendor white paper over the last two years.
BGov readily acknowledges that there are hundreds of millions, if not billions, of dollars spent on components that would go into a zero trust architecture.
The evidence of that spending and push toward modernizing the federal approach to cybersecurity seems to be everywhere, especially over the past year as agency chief information officers and others have realized the value and potential of changing their approach to network defenses. The COVID-19 pandemic reminded and reinforced the power of identity and access management as a key piece to defend against cyber attacks.
The National Institute of Standards and Technology is reviewing concept papers for how to implement a zero trust architecture across six scenarios.
This project will focus primarily on access to enterprise resources. More specifically, the focus will be on behaviors of enterprise employees, contractors and guests accessing enterprise resources while connected from the corporate (or enterprise headquarters) network, a branch office, or the public internet, NISTs National Cybersecurity Center of Excellence wrote in the project description. Access requests can occur over both the enterprise-owned part of the infrastructure as well as the public/non-enterprise-owned part of the infrastructure. This requires that all access requests be secure, authorized, and verified before access is enforced, regardless of where the request is initiated or where the resources are located.
NIST said based on its review of the white papers, it plans to issue a cooperative research and development agreement (CRADA) to demonstrate different approaches to zero trust.
The Department of Homeland Security and the National Security Agency are among two of the agencies on the leading edge to do more than test these concepts.
Beth Cappello, the DHS deputy CIO, said the agency is using its target architecture initiative, which sets a common technology baseline to let programs adopt new technologies quickly, to implement zero trust components.
By rapidly implementing IT and security improvements to reduce risk, it will help the Office of the CIO address the remote work posture of our employees. Components have been able to take our target zero trust architecture and quickly customize or tailor it to field similar capabilities within their respective environments, Cappello said at the recent MicroStrategy World 2021 conference on Feb. 4. From a technology perspective, the zero trust architecture approach allow us to ensure we have a dynamic, on-demand chain of trust that is continually reassessed at each access point. Frankly, in our continued remote environment, this is incredibly important.
Homeland Securitys approach to zero trust is all about reusable architecture guides that are focused on user needs and developed with the components in mind.
Cappello said policy templates, pattern libraries and reference implementations also help to ensure DHS is implementing zero trust concepts in a standard way. The DHS zero trust action group which is made up of experts from across the agency is leading the coordinating, developing and sharing of these documents and individual experiences.
Thus far, we have fielded seven zero trust use cases to enhance access to IT assets and systems, she said. These use cases augment security while also reducing the load on our VPN connection points. This zero trust architecture approach also increases our network performance by leveraging a cloud access security broker and cloud security gateway capabilities to give users secure, direct access to cloud managed applications thereby reducing traffic on that Homeland Security enterprise network.
NSA is taking a similar approach as DHS, providing policies and reusable components as part of its zero trust approach.
Timothy Clyde, the lead systems engineer for NSAs external identity solutions and service offerings, said at the recent SailPoint Evolution of Identity conference that the agency launched a zero trust pilot just over a year ago with the goal of figuring out how to get users the data they need when they need it no matter the current set of policies and rules.
What is the level of trust that needs to go with that identity? Clyde asked. Depending on what the level of trust is that needs to be with that identity, comes the governance above that identity. Weve used policy engines. We tag our data and have been doing it successfully now for well over a decade. Some people would argue once you have a solid identity for the person, the device and the data, the policy then becomes probably the most important piece of it. It does need to be dynamic enough, that depending on the environment, you may have two policies that are almost identical. But if you are in Environment A, you may have access, but if you are in Environment B, you may not.
Clyde said the initial phase and roll out of the zero trust pilot includes a lab to test technology components for DoD partners and NSA also is making its policy engines available for others to use in their environments.
Neal Ziring, the technical director for NSAs Cybersecurity directorate, said the agencies can use policy engines to underpin the process to decide who is granted access to information. He said the policy is at the heart of access control.
Policy administrators create the rules that allow (or not allow) people and systems to access data. In a zero trust architecture, when a user makes a request to access data, the request is sent to a policy information point (PIP). The PIP provides the user information (such as attributes, clearance level, where they are located, etc.) to a policy decision point (PDP). The PDP analyzes this information along with additional policy rules regarding who can access that data, and determines if that user on that device is allowed to access that data. The PDP then delivers this decision to a policy enforcement point (PEP) who is the final authority on whether or not that user or device gets access to that data and either allows or disallows access, Ziring said in an email to Federal News Network. These PIP, PDP and PEP sub processes, when combined, are commonly referred to as the zero trust policy engine.
The zero trust pilot is a joint effort amongst U.S. Cyber Command, the Defense Information Systems Agency and NSA where they are researching, developing, piloting and lab testing technologies.
The team has been able to demonstrate the effectiveness of zero trust at preventing, detecting, responding and recovering from cyberattacks, Ziring said. NSA is part of the joint team developing the DoD zero trust reference architecture. NSA is developing zero trust best practices and guidance to share with a broader set of US critical network owners, such as National Security System owners. NSA is working with the DoD CIO and DISA to update any existing cybersecurity policies as applicable to include zero trust principles to ensure that all of DoD is synchronized on zero trust, and implements zero trust in a secure and standard way across the department to protect critical information.
He added the DoDwide working group is partnering with NIST to ensure the guidance on zero trust are in alignment across government.
Under the pilot, NSA and U.S. Cyber Command established an unclassified lab at DreamPort, a public-private innovation partnership that hosts zero trust equipment and simulates customer environments where they test diverse configurations of zero trust implementations.
Ziring said it also serves as a location to hold unclassified discussions with zero trust stakeholders, such as government customers and vendors.
The ability to engage with our stakeholders at the lowest possible classification level allows for broader engagements across the community and an increased understanding of cybersecurity as it evolves, he said. We have a separate testbed with DISA that will host any anticipated classified information.
More here:
DHS, NSA creating reusable pieces to zero trust foundation - Federal News Network
- SC Quashes NSA Detention of Main Accused in 2024 Sambhal Violence, Imposes Rs 10 Lakh Cost on BJP Govt in UP - TheWire.in - September 29th, 2026 [September 29th, 2026]
- Rush Hour: NSA detention of Sambhal violence accused quashed, cartoonists content withheld and more - Scroll.in - September 29th, 2026 [September 29th, 2026]
- Another NSA order of UP govt quashed, SC orders immediate release of 2024 Sambhal violence accused - theprint.in - September 29th, 2026 [September 29th, 2026]
- NSA Demands Centre, State Action Over Killings, Arson and Displacement of Nagas - Ukhrul Times - September 29th, 2026 [September 29th, 2026]
- World Cup Visa Scandal: Nobody at the NSA will be protected - Sports Minister - Modern Ghana - September 22nd, 2026 [September 22nd, 2026]
- NSA Ajit Doval Recounts Moment He Feared the End of His Career - NDTV - September 22nd, 2026 [September 22nd, 2026]
- Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI - The Record from Recorded Future News - September 15th, 2026 [September 15th, 2026]
- United States NSA recruits psychologists in bid to boost its appeal to new blood - Intelligence Online - September 15th, 2026 [September 15th, 2026]
- NSA releases best practices guide on cyber hygiene for defending against advanced threats - American Hospital Association - September 15th, 2026 [September 15th, 2026]
- United States NSA recruits psychologists in bid to boost its appeal to new blood - Intelligence Online - September 15th, 2026 [September 15th, 2026]
- NSA, FBI & CISA Issue Advisory on China-Based AI Distillation Campaigns - ExecutiveGov - September 15th, 2026 [September 15th, 2026]
- NSA, FBI & CISA Issue Advisory on China-Based AI Distillation Campaigns - ExecutiveGov - September 15th, 2026 [September 15th, 2026]
- NSA set to get five new organizations - Breakingthenews.net - September 15th, 2026 [September 15th, 2026]
- FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are reportedly carrying out 'industrial-scale' distillation campaigns to boost their... - September 15th, 2026 [September 15th, 2026]
- Confused about which VPN is right, US senator asks the NSA for guidance - Ars Technica - September 4th, 2026 [September 4th, 2026]
- Former NSA cybersecurity official: Pro-China 'influence operations' and 'cognitive warfare' work in protests against data centers and Flock cameras -... - September 4th, 2026 [September 4th, 2026]
- Can the county home to the NSA and US Cyber Command ban data centers? - The Baltimore Banner - September 4th, 2026 [September 4th, 2026]
- Family proud of her work for poor: DU students father after HC quashes NSA case - The Times of India - September 4th, 2026 [September 4th, 2026]
- Man who cut down Flock camera in St. Johns County claimed he was working with the NSA - Action News Jax - September 4th, 2026 [September 4th, 2026]
- Lucknow journalist Satyam Verma to move Allahabad high court after fellow NSA accused Aakriti gets relief - The Times of India - September 4th, 2026 [September 4th, 2026]
- NSA Board Dissolution: Olympic, Paralympic representation expected to remain on new board - 3News - September 4th, 2026 [September 4th, 2026]
- NSA Joins FBI in Issuing Warning about Chinese Hacking Group QTFY Cyber Activity - National Security Agency (.gov) - September 2nd, 2026 [September 2nd, 2026]
- NSA and FBI Warn Chinese Hackers Are Actively Targeting US Critical Infrastructure - LinkedIn - September 2nd, 2026 [September 2nd, 2026]
- UP firecracker blast toll climbs to 13; NSA invoked against accused - Daily Pioneer - September 2nd, 2026 [September 2nd, 2026]
- Man Accused of Impersonating Chief Justice Roberts, NSA Agent - Bloomberg Law News - August 25th, 2026 [August 25th, 2026]
- I Worked For The NSA For Years. Here's What Happened To My Life After Donald Trump And DOGE Showed Up Last Year. - HuffPost - August 25th, 2026 [August 25th, 2026]
- NSA isnt complying with federal laws on whistleblower protections, IG finds - Federal News Network - August 25th, 2026 [August 25th, 2026]
- NSA Doval says India-China ties 'returning to normalcy' as he holds key talks with Wang Yi on border issue - The New Indian Express - August 25th, 2026 [August 25th, 2026]
- 4 Ways Tim Kosiba and the NSA Are Countering the Chinese Intelligence Threat - GovCon Wire - August 25th, 2026 [August 25th, 2026]
- Man charged with forging Chief Justice John Robertss signature, impersonating NSA agent - Yahoo - August 25th, 2026 [August 25th, 2026]
- NSA Doval to visit China on Monday to attend Special Representatives talks with FM Wang - The Economic Times - August 25th, 2026 [August 25th, 2026]
- Audit Finds Lack of Oversight of NDAs at NSA - FEDweek - August 25th, 2026 [August 25th, 2026]
- Redefining India-China Relations: NSA Dovals Visit to Beijing May Provide the Breakthrough - Raksha Anirveda - August 25th, 2026 [August 25th, 2026]
- NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology - The Record from Recorded Future News - August 25th, 2026 [August 25th, 2026]
- NSA Doval meets Chinese Vice President Han Zheng ahead of border talks - The Tribune - August 25th, 2026 [August 25th, 2026]
- India-China ties normalised by peace on border, says NSA Doval at talks with Wang Yi - Firstpost - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval holds 25th India-China border talks with Wang Yi - timesofindia.indiatimes.com - August 25th, 2026 [August 25th, 2026]
- NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs - Security Affairs - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval arrives in Beijing, set for border talks with Chinas Wang Yi on August 25 - The Hindu - August 25th, 2026 [August 25th, 2026]
- NSA, FBI Warn of AI-Powered Attacks on Industrial Systems Targeting Siemens PLCs - finance.biggo.com - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval holds talks with Chinese FM Wang Yi on boundary issue - News On AIR - August 25th, 2026 [August 25th, 2026]
- NSA Doval in Beijing for Talks with Chinese FM - Kashmir Observer - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval to hold India-China boundary talks with Wang Yi in Beijing - The New Indian Express - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval to hold border talks with Chinese Foreign Minister Wang on Tuesday - The Tribune - August 25th, 2026 [August 25th, 2026]
- Ayitey Powers Arrested Over Alleged Death Threat Against NSA Boss - Modern Ghana - August 25th, 2026 [August 25th, 2026]
- NSA Doval arrives in Beijing for talks with Chinese FM Wang Yi on boundary issue - ThePrint - August 25th, 2026 [August 25th, 2026]
- Police arrest former boxer Ayitey Powers over alleged death threat on NSA boss - Ghanaian Times - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval in Beijing for boundary talks - Awaz The Voice - August 25th, 2026 [August 25th, 2026]
- ID Based on Anonymous Informant, Sudden Reference to 2009 Home Ministry Notification: Why NSA Case Against Satyam Verma Is Unconvincing - TheWire.in - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval: India's Strength Infused with Tolerance Amid Military Actions - India News Network - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval Reveals Operation Sindoor Strategy in New Discovery Docuseries - Daily Pioneer - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval on Operation Sindoor: 'India can hit hard, irrespective of consequences' - wionews.com - August 16th, 2026 [August 16th, 2026]
- Indias generosity, tolerance should not be mistaken for weakness: NSA Ajit Doval on Op Sindoor - The Tribune - August 14th, 2026 [August 14th, 2026]
- 'Don't mistake India's generosity with weakness': NSA Ajit Doval on Operation Sindoor - The Times of India - August 14th, 2026 [August 14th, 2026]
- India's generosity, tolerance should not be mistaken for weakness: NSA Ajit Doval on Operation Sindoor - The Hindu - August 14th, 2026 [August 14th, 2026]
- Former NSA Chief Gen. Paul Nakasone: AI Is Changing the Cyber Battlefield - The Cipher Brief - August 14th, 2026 [August 14th, 2026]
- NSA Doval says Indias restraint should not be mistaken for weakness - Awaz The Voice - August 14th, 2026 [August 14th, 2026]
- NSA Ajit Doval says India can hit hard irrespective of consequences in first post-Sindoor interview - The Economic Times - August 14th, 2026 [August 14th, 2026]
- Man claiming to be undercover agent of NSA Ajit Doval arrested in Bihar - The Hindu - August 14th, 2026 [August 14th, 2026]
- Indias tolerance should not be mistaken for weakness; can take risks, hit hard: NSA Doval on Op Sindoor - The Kashmir Horizon - August 14th, 2026 [August 14th, 2026]
- Indias Tolerance Not a Sign of Weakness: NSA Ajit Doval on Operation Sindoor - The CSR Journal - August 14th, 2026 [August 14th, 2026]
- NSA Joins FBI and Others in Releasing Guidance to Defend Against Gunra Ransomware - National Security Agency (NSA) (.gov) - August 12th, 2026 [August 12th, 2026]
- Your router is probably vulnerable to the same attacks the NSA just warned about - MakeUseOf - August 12th, 2026 [August 12th, 2026]
- Trump has to accept hes going to lose Iran war: Former deputy NSA - MS NOW - August 12th, 2026 [August 12th, 2026]
- NSA installs DHS lawyer as new general counsel - The Record from Recorded Future News - August 12th, 2026 [August 12th, 2026]
- Manipur to invoke NSA against NH extortionists: Min - The Times of India - August 12th, 2026 [August 12th, 2026]
- Spymaster United States Joshua Rudd, US special forces officer nursing NSA back to health - Intelligence Online - July 7th, 2026 [July 7th, 2026]
- Capability, Not Compute: NSA Discretion in the Frontier AI EO - The Well News - July 7th, 2026 [July 7th, 2026]
- NSA partners with dog walking app to tackle livestock worrying - Agriland UK - July 1st, 2026 [July 1st, 2026]
- Youth Round Table Discussion: Youth round table discussion held at NSA - Myanmar International TV - July 1st, 2026 [July 1st, 2026]
- NSA welcomes Farming Roadmap 2050 and says farmers are ready to meet the challenge - Meat Management - July 1st, 2026 [July 1st, 2026]
- Crypto Executive Disputes Claims Anthropics Mythos Breached NSA Systems - Yahoo Tech - June 22nd, 2026 [June 22nd, 2026]
- Crypto Executive Disputes Claims Anthropics Mythos Breached NSA Systems - BeInCrypto - June 22nd, 2026 [June 22nd, 2026]
- Its more than Iran could have ever hoped for: Ex-US NSA John Bolton on US-Iran deal - Firstpost - June 22nd, 2026 [June 22nd, 2026]
- Manipur slaps NSA on youth already held under UAPA. Why HC quashed both cases, ordered his release - ThePrint - June 22nd, 2026 [June 22nd, 2026]
- Algorand Post-Quantum Security by 2027: 3 Years Ahead of NSA - The Cryptonomist - June 22nd, 2026 [June 22nd, 2026]
- China foreign minister set to attend Brics NSA meet in Delhi next week - The Times of India - June 22nd, 2026 [June 22nd, 2026]
- India to host BRICS NSA meet on June 2223: MEA - Awaz The Voice - June 22nd, 2026 [June 22nd, 2026]
- IDR Final Rule updates NSA dispute resolution | United States | Global law firm - Norton Rose Fulbright - June 16th, 2026 [June 16th, 2026]
- Where Is Edward Snowden Now? What to Know About the NSA Whistleblower's Life in Exile, 13 Years Later - People.com - June 16th, 2026 [June 16th, 2026]