Zero Trust Devices
Last updated on
Purpose
Section titled “Purpose”Zero Trust Devices ensures that endpoint posture is continuously validated before users or operators can access workloads, control planes, or sensitive data.
Control objectives
Section titled “Control objectives”- Verified endpoint identity: Every managed device can be uniquely identified and tied to a responsible user or operator.
- Posture-based access: Access decisions include endpoint state such as patch level, disk encryption, and active security controls.
- Session trust continuity: Device trust is re-evaluated during sessions, not only at login.
- Separation of unmanaged endpoints: Sensitive operations are restricted to compliant and managed device classes.
Design recommendations
Section titled “Design recommendations”- Define device classes: Separate privileged admin endpoints, standard workforce devices, and automation jump hosts.
- Apply conditional access: Enforce access conditions based on endpoint compliance and user risk.
- Harden administration paths: Use dedicated admin workstations for privileged operations and emergency access workflows.
- Protect credentials on endpoints: Minimize token persistence and enforce phishing-resistant authentication where possible.
Implementation checkpoints
Section titled “Implementation checkpoints”- Device baseline policy: Mandatory controls for patching, endpoint protection, encryption, and local admin rights.
- Access policy matrix: Explicit mapping of workload criticality to allowed device classes.
- Exception governance: Time-boxed and approved exceptions for unmanaged or non-compliant endpoints.
- Evidence model: Auditable records for endpoint posture checks and denied access decisions.
STACKIT references
Section titled “STACKIT references”- Access and Identity: Documentation
- Security hardening guidance: Documentation
Anti-patterns to avoid
Section titled “Anti-patterns to avoid”- Trust by VPN alone: Network location is treated as proof of endpoint trust.
- Permanent exceptions: Non-compliant devices remain allowed without expiry or owner accountability.
- Unsegmented admin endpoints: Privileged operations happen from standard user devices.