Zero Trust Architecture for Enterprise Network Security: Implementation Framework, Identity-Aware Micro-Segmentation, and Empirical Evaluation across 12 Kerala Organisations

Sreejith K Nambiar, Priya R Krishnan, Anish N Pillai

Abstract


Zero Trust Architecture (ZTA) — the security model predicated on theprinciple of "never trust, always verify" that eliminates implicit trust for anyuser, device, or network location and enforces continuous verification ofidentity, device health, and access authorisation for every resource accessrequest — has emerged as the dominant enterprise cybersecurity paradigmresponse to the inadequacy of perimeter-based security models in the face of cloud migration, remote working, mobile device proliferation, and thesustained erosion of network perimeter relevance by supply chain attacks,insider threats, and credential-based intrusions. NIST Special Publication800-207 (2020) formalised the ZTA framework through seven tenets governing resource access decisions based on dynamic policy evaluation of user identity, device posture, network location, requested resource sensitivity, and behavioural analytics. This implementation and evaluation study documents the phased ZTA deployment — comprising identity provider integration (Okta OIDC/SAML2), device health attestation (Microsoft Intune MDM), network micro-segmentation (Palo Alto Prisma Access), and continuous monitoring (SIEM + UEBA) — across 12 Kerala IT and financial services organisations over an 18-month period, measuring security incident counts across five attack categories in the 6-month pre-implementation baseline and 6-month post-implementation follow-up periods. ZTA implementation produced statistically significant reductions across all five attack categories: unauthorised access attempts (?87.5%, 48?6 incidents), lateral movement (?91.2%, 34?3), data exfiltration (?90.9%, 22?2), phishing success rate (?71.0%, 62?18 users compromised), and malware execution (?78.9%,38?8 incidents), with all reductions significant at p < 0.001. The mostsignificant implementation challenge was user authentication friction: initialZTA deployment increased mean authentication steps from 1.8 to 3.6 persession, reducing user satisfaction from 7.8 to 5.4/10, partially recovered to6.8/10 through adaptive MFA configuration that reduced step-upauthentication to 1.9 steps for low-risk sessions. KEYWORDS: Zero Trust Architecture, ZTA, Enterprise security, Micro-segmentation, Identity verification, SASE, MFA, NIST 800-207, Kerala,Cybersecurity, Network defence, Cloud security

Full Text:

PDF 12-22

Refbacks

  • There are currently no refbacks.