ChaptersEventsBlog
How is your enterprise using AI Agents? Help us benchmark security and take the survey before November 30 →

Download Publication

Defining the Zero Trust Protect Surface
Defining the Zero Trust Protect Surface
Who it's for:
  • Zero Trust Architects and Implementation Teams
  • CISOs and other CxOs
  • Information Security Managers and Analysts
  • Privacy and Compliance Officers
  • IT Auditors and Assessors
  • Software Developers
  • Network Security Engineers

Defining the Zero Trust Protect Surface

Release Date: 03/05/2024

Working Group: Zero Trust

Enterprise adoption and implementation of Zero Trust is broad and growing. Venture Beat reports that 90% of organizations moving to the cloud are adopting a Zero Trust strategy, while Gartner predicts that 10% of large enterprises will have a mature and measurable Zero Trust security program in place by 2026. How is a mature Zero Trust program achieved? The NSTAC Report to the President on Zero Trust and Trusted Identity Management outlines a five-step process. 

This publication by the CSA Zero Trust Working Group provides guidance on iteratively executing the first step of the Zero Trust implementation process, “Defining the Protect Surface.” Defining the protect surface entails identifying, categorizing, and assessing an organization's data, applications, assets, and services (DAAS); business risk; and current security maturity. In this document, readers will find valuable guidance that starts their Zero Trust security journey on the right path.

Key Takeaways: 
  • The definition of Zero Trust and the Zero Trust protect surface
  • How to initiate the Zero Trust implementation process by defining, analyzing, and prioritizing the organization’s protect surfaces
  • How to identify the DAAS elements to be protected
  • The risks and potential impacts of protect surface compromises
  • The difference between the attack surface and the protect surface
Download this Resource

Bookmark
Share
Related resources
Managing Privileged Access in a Cloud-First World
Managing Privileged Access in a Cloud-First World
AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) v1.0.2
AI Consensus Assessments Initiative Questionnai...
Analyzing Log Data with AI Models to Meet Zero Trust Principles
Analyzing Log Data with AI Models to Meet Zero ...
MCP Can Be RCE for You and Me
MCP Can Be RCE for You and Me
Published: 11/25/2025
The 99% Solution: MFA for Hypervisor Security
The 99% Solution: MFA for Hypervisor Security
Published: 11/18/2025
From Chatbots to Agents: The Evolution Toward Agentic AI
From Chatbots to Agents: The Evolution Toward Agentic AI
Published: 11/13/2025
Rethinking AI Security: Every Interaction is About Identity
Rethinking AI Security: Every Interaction is About Identity
Published: 11/07/2025

Interested in helping develop research with CSA?

Related Certificates & Training