Security & governance · Glossary term
What is Zero Trust?
A security model that grants no implicit trust from network location or asset ownership and instead evaluates each access request against identity, device, resource, policy, and current context.
Why does Zero Trust matter?
AI tools and agents span local files, cloud services, models, and external content, so a trusted internal network is too broad a basis for authority.
Zero Trust in practice
Authenticate every actor and workload, authorize each resource action, issue short-lived credentials, segment access, and continuously record and reevaluate policy-relevant signals.
What is the common confusion about Zero Trust?
Zero trust does not mean trusting nothing or blocking all automation. It means making trust decisions explicit, scoped, and continuously verifiable.
Learn Zero Trust in the course
Start with
- Security — Secrets, API Key Rotation, Audit Logs, Guardrails
Eliminate secret sprawl via centralized vaults (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault). Never store credentials in config files, env files in VCS, spreadsheets.
Taught in Phase 17: Infrastructure & Production.
Related terms
- Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.
- Trust BoundaryAn interface where data, instructions, identity, or authority crosses between components or principals that operate under different trust…
- Approval GateA control point that blocks a consequential action until an authorized person or policy grants permission.
- Audit LogA durable, access-controlled record of security- or accountability-relevant events, including who or what acted, what changed, when it…
Sources
More terms in Security & governance
- AI Risk Assessment
- Audit Log
- Content Provenance
- Data Classification
- Data Exfiltration
- Data Lineage
- Data Minimization
- Datasheet for Datasets
- Defense in Depth
- Indirect Prompt Injection
- Jailbreak
- Membership Inference
- Provenance Attestation
- Purpose Limitation
- Red Teaming
- Separation of Duties
- Software Bill of Materials (SBOM)
- Threat Model
- Trust Boundary
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.