IS 19835:2026
Zero Trust Architecture (ZTA) — Implementation Framework
This Indian Standard provides a comprehensive implementation framework for Zero Trust Architecture (ZTA) to strengthen cybersecurity in organizations operating across on-premises, cloud, and hybrid digital environments. Unlike traditional security models that assume users and devices inside an organization’s network are trustworthy, Zero Trust follows the principle of “Never Trust, Always Verify.” Every user, device, application, and service requesting access must be continuously authenticated, authorized, and validated before being granted the minimum level of access required.
This explains the core principles of Zero Trust, including identity-based access control, multi-factor authentication, least-privilege access, continuous monitoring, contextual risk assessment, and secure communication irrespective of network location. It also describes essential architectural components such as identity management, authentication and authorization, policy administration and enforcement, observability, security monitoring, and policy orchestration to enable dynamic access decisions.
In addition, it presents implementation patterns such as service access gateways, micro-segmentation, nano-segmentation, software-defined perimeters, and service mesh architectures that help reduce attack surfaces and prevent unauthorized lateral movement within networks. It also introduces a Zero Trust maturity model, migration strategy, and assessment methodology to help organizations evaluate their cybersecurity readiness, identify improvement areas, and progressively adopt Zero Trust practices.
Overall, this standard serves as a practical guide for government bodies, enterprises, and other organizations to design, implement, monitor, and continuously improve a resilient cybersecurity framework capable of protecting critical digital assets against evolving cyber threats.
Last Updated on August 6, 2026