RackTop Systems
Federal & Defense

Zero Trust reaches the data pillar

What Zero Trust security is, where it came from, and how the CISA and DoD Zero Trust Maturity Models differ, who each applies to, and why both converge on the data pillar.

RackTop SystemsJuly 12, 20269 min read

Key takeaways

  • Zero Trust security replaces implicit, location-based trust with continuous verification of every user, device, and request. NIST SP 800-207 defines the architecture.
  • There are two dominant Zero Trust Maturity Models: CISA’s (5 pillars plus 3 cross-cutting capabilities, four maturity stages, for federal civilian agencies) and DoD’s (7 pillars, 45 capabilities, 152 activities, with a Target Level deadline of FY2027).
  • CISA’s model is a descriptive roadmap; the DoD model is a prescriptive execution plan. Both make data a pillar in its own right.
  • Identity and network matured first almost everywhere. The data pillar, especially unstructured data on file shares, is where most Zero Trust programs are weakest today.
  • Optimal data-pillar maturity means continuous, attribute-based evaluation of every file operation, with detection, response, and immutable recovery living at the storage layer.

Zero Trust began, in most organizations, as a network and identity initiative. Federal strategy has since made explicit what practitioners already knew: the model only works if it reaches the data. Both of the maturity models that now define Zero Trust in practice, CISA’s and the DoD’s, make data a pillar in its own right, and for most programs it is the pillar furthest from mature. This article explains what Zero Trust security actually is, where it came from, how the two Zero Trust Maturity Models differ and who each applies to, and what reaching maturity on the data pillar takes.

What is Zero Trust security?

Zero Trust security is a model that grants no implicit trust based on where a user or system sits. Every request to access a resource is verified continuously, against identity, device, context, and policy, no matter whether it originates outside the network or from a machine ten feet from the data center. The operating assumptions are simple: assume the network is already compromised, verify explicitly, and grant the least privilege necessary for the task at hand.

The formal definition comes from NIST Special Publication 800-207, which describes Zero Trust Architecture as a set of principles rather than a product: all data sources and services are resources, access is granted per session, trust is evaluated dynamically from as many signals as available, and the enterprise monitors the integrity and behavior of everything it owns. The phrase to hold onto is per session and per request. A login is not a lifetime pass; in a Zero Trust Architecture, trust is re-earned continuously.

A short history of Zero Trust

The history of Zero Trust runs about two decades. In 2004, the Jericho Forum began arguing for “de-perimeterization,” the then-heretical idea that the network boundary could not be the primary security control. In 2010, John Kindervag at Forrester Research coined the term Zero Trust and its slogan, never trust, always verify, arguing that the soft interior behind a hard perimeter was exactly what attackers exploited. Google’s BeyondCorp initiative, launched after the 2009 Aurora intrusion and published in a series of papers beginning in 2014, proved the model at scale by moving employee access off the trusted network entirely.

Government then turned the concept into policy. NIST SP 800-207 (August 2020) gave Zero Trust Architecture its canonical definition. Executive Order 14028 (May 2021), issued in the wake of SolarWinds and Colonial Pipeline, ordered federal agencies to adopt it. OMB Memorandum M-22-09 (January 2022) set concrete Zero Trust goals for federal civilian agencies, the DoD published its Zero Trust Strategy in November 2022, and CISA released version 2.0 of its Zero Trust Maturity Model in April 2023. In roughly twelve years, Zero Trust went from a Forrester paper to a contractual and budgetary reality across the U.S. government.

What is a Zero Trust Maturity Model?

A Zero Trust Maturity Model is a framework for measuring how far an organization has actually traveled from perimeter-based security toward the Zero Trust ideal, and what the next increment of progress looks like. Instead of treating Zero Trust as a binary you either have or lack, a maturity model breaks the architecture into pillars, typically identity, devices, networks, applications, and data, and defines observable stages of capability within each. Two models dominate in practice, and understanding both matters because they shape procurement, accreditation, and roadmaps well beyond the agencies they formally bind.

The CISA Zero Trust Maturity Model

CISA’s Zero Trust Maturity Model, now at version 2.0 (April 2023), was written to help federal civilian executive branch (FCEB) agencies meet the mandates of Executive Order 14028 and OMB M-22-09, and it has become the de facto reference for state and local government and much of the private sector as well.

The model organizes Zero Trust into five pillars: Identity, Devices, Networks, Applications and Workloads, and Data. Three cross-cutting capabilities run through all five: Visibility and Analytics, Automation and Orchestration, and Governance. Within each pillar, an organization assesses itself against four maturity stages: Traditional (perimeter thinking, manual processes), Initial (first automation and cross-pillar integration), Advanced (centralized, coordinated control with some automated responses), and Optimal (fully automated, dynamic, continuously evaluated policy). The model is deliberately descriptive rather than prescriptive: it tells you what better looks like at each stage and lets each agency chart its own route and pace, with M-22-09 supplying the near-term deadlines.

The DoD Zero Trust model

The Department of War (DoW, formerly DoD) took a different approach, shaped by a different adversary model: nation-state actors already assumed to be inside the network. The DoD Zero Trust Strategy (November 2022), together with its Reference Architecture and Capability Execution Roadmap, defines seven pillars: User, Device, Network and Environment, Applications and Workloads, Data, Automation and Orchestration, and Visibility and Analytics. Where CISA treats automation and visibility as cross-cutting themes, the DoD model promotes them to full pillars.

The DoD model is also far more granular and far more prescriptive. The seven pillars decompose into 45 capabilities and 152 activities, each with defined outcomes. Two achievement levels replace CISA’s four stages: Target Level Zero Trust, the 91 activities every DoW component must complete by the end of fiscal year 2027, and Advanced Level, all 152 activities, for systems and missions that warrant it. This is not a self-paced journey guide; it is an execution plan with owners, sequencing, and a deadline, and its expectations increasingly flow outward to the Defense Industrial Base and mission partners whose systems touch DoW data.

CISA vs DoD: same destination, different maps

The two models describe the same architecture from different postures. CISA wrote a maturity model in the classic sense, a map for agencies at very different starting points; the DoW wrote a war plan, with numbered objectives and a date. Which one applies to you follows from who you are: FCEB agencies are measured against CISA’s model, DoW components and their supporting contractors against the DoD model, and commercial organizations are free to use either, though most reach for CISA’s as the more general-purpose reference. The structural differences are easiest to see side by side:

CISA ZTMM v2.0DoD Zero Trust Strategy
Owner and audienceCISA, for federal civilian (FCEB) agencies; widely adopted by state, local, and commercial organizationsDoW CIO, for DoW components; expectations flow to the DIB and mission partners
Structure5 pillars plus 3 cross-cutting capabilities7 pillars, 45 capabilities, 152 activities
Maturity scaleFour stages per pillar: Traditional, Initial, Advanced, OptimalTwo levels: Target (91 activities) and Advanced (all 152)
DeadlinesJourney-based; near-term goals set separately by OMB M-22-09Target Level required across the DoW by end of FY2027
CharacterDescriptive roadmap: where you are, what better looks likePrescriptive execution plan: specific activities, owners, and sequencing
Data pillarOne of five pillars; Optimal means dynamic access, encryption, and automated categorizationOne of seven pillars; capabilities include tagging, DLP, rights management, and granular access
CISA and DoD Zero Trust pillars comparedTwo columns of pillars. The CISA Zero Trust Maturity Model has five pillars: identity, devices, networks, applications and workloads, and data, plus three cross-cutting capabilities: visibility and analytics, automation and orchestration, and governance. The DoD model has seven pillars: user, device, network and environment, applications and workloads, data, automation and orchestration, and visibility and analytics. The data pillar is highlighted in both models.Same architecture, two mapsCISA ZTMM v2.05 pillars + 3 cross-cuttingDoD Zero Trust7 pillars, 45 capabilitiesIdentityUserDevicesDeviceNetworksNetwork & EnvironmentApplications & WorkloadsApplications & WorkloadsDataDataAutomation & OrchestrationVisibility & AnalyticsCross-cutting capabilities in CISA's model:Visibility & Analytics · Automation & Orchestration· Governance ·DoD promotes automation and visibility to full pillars. Both models make data a pillar in its own right.
CISA’s five pillars and DoD’s seven describe the same architecture. Both make data a pillar in its own right.

The data pillar: where both models converge

Strip away the structural differences and the two models agree on the destination that matters most: the data. CISA’s data pillar at Optimal maturity calls for continuous, dynamic access decisions, encryption of data at rest and in transit everywhere, automated categorization and labeling, and inventoried, monitored data holdings. The DoD data pillar decomposes into capabilities that will sound familiar to anyone who has read a CUI or classified-handling requirement: a data catalog, tagging and labeling, data loss prevention, encryption and rights management, and granular, attribute-driven access control.

There is a reason both models save data for last in most real-world roadmaps, and it is not the ordering of the pillars. Identity and network were the mature markets: agencies could buy MFA, SSO, and micro-segmentation and show progress quickly. The data pillar is harder because the data itself is sprawling and unstructured, spread across file shares and NAS platforms that predate the program, touched by every user and application, and served by storage that was never designed to evaluate trust. A Zero Trust program that stops at the network has secured the roads and left the warehouse unlocked.

Applied to unstructured data, data-pillar maturity means every file operation is evaluated against current policy, user, clearance, program, device, and context, with no implicit trust granted by a prior login. It means malicious behavior against that data is detected and stopped inline, and it means recovery points exist that survive even administrative compromise.

What optimal data-pillar maturity looks like in practice

These are storage-layer properties, and they map directly onto the language of both maturity models. Attribute-based access control enforced on every SMB, NFS, S3, and Web Drive operation is the “dynamic, granular access” both models describe, evaluated per request as NIST SP 800-207 demands. Behavioral analytics scoring every read and write against each identity’s baseline is the data pillar’s share of Visibility and Analytics. Inline response, terminating a hostile session in under a second, is Automation and Orchestration operating at the only layer where it can act before damage lands. FIPS 140-3 validated encryption with per-dataset keys satisfies the encryption capabilities, and an immutable, per-operation audit record supplies the evidence trail Governance requires. This is why data-centric Zero Trust and Cyberstorage describe the same architecture from two directions, and it is the architecture BrickStor SP was built to provide.

For agencies and integrators, building these controls into the storage platform also carries an accreditation dividend: real-time logging, attribute-based access control, validated encryption, and immutable audit are present by design rather than assembled from separate tools, which supports faster initial Authorization to Operate and a continuous-accreditation posture as both maturity models tighten.

Frequently asked questions

Zero Trust security is a model that grants no implicit trust based on network location or prior authentication. Every request is verified continuously against identity, device health, context, and policy, with least-privilege access and the working assumption that the network is already compromised. NIST SP 800-207 defines the reference Zero Trust Architecture, and the CISA and DoD Zero Trust Maturity Models measure progress toward it.
A Zero Trust Maturity Model is a framework for assessing how far an organization has progressed from perimeter-based security toward Zero Trust, pillar by pillar. CISA’s model, the most widely used, defines five pillars (Identity, Devices, Networks, Applications and Workloads, Data) with four maturity stages from Traditional to Optimal, plus three cross-cutting capabilities. The DoD publishes its own, more prescriptive model with seven pillars, 45 capabilities, and 152 activities.
Audience, structure, and posture. CISA’s model serves federal civilian agencies (and, informally, everyone else) as a descriptive roadmap: five pillars, four maturity stages, self-paced with OMB deadlines set separately. The DoD model governs DoW components as a prescriptive execution plan: seven pillars (automation and visibility are promoted from cross-cutting themes to pillars), 152 defined activities, and a hard requirement to reach Target Level Zero Trust by the end of FY2027. Both models make data a dedicated pillar.
John Kindervag coined the term and the model at Forrester Research in 2010, building on the Jericho Forum’s earlier de-perimeterization work from 2004. Google’s BeyondCorp program proved the approach at production scale, and NIST SP 800-207 (2020) turned it into the formal Zero Trust Architecture that federal policy now mandates.
No. Zero Trust is an architecture and a set of principles applied across identity, devices, networks, applications, and data. Products implement pieces of it: an identity provider covers part of the identity pillar, micro-segmentation part of the network pillar, and Cyberstorage the data pillar. Any single product marketed as “Zero Trust in a box” is, at best, one pillar of five.
Storage is where the data pillar becomes real. A storage platform participating in Zero Trust evaluates every file operation against attribute-based policy per request, watches behavior continuously for both encryption and theft patterns, responds inline, encrypts with validated cryptography, and keeps an immutable audit record. BrickStor SP implements this across SMB, NFS, S3, and Web Drive, which is why data-centric Zero Trust and Cyberstorage describe the same architecture.

See data-layer defense in action

A 30-minute demo shows Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your environment.

Zero Trust Maturity Model: CISA vs DoD Compared | RackTop Systems