- Home
- All questions
- Question 193
CISSP study material · question 193 of 500
A vendor claims its product delivers zero trust because it removes the perimeter firewall. Why does NIST SP 800-207 reject definitions framed this way?
Show the answer
Answer: A. It defines zero trust by seven tenets that should be present, not by what has been removed, and accepts not all will be realised purely.
SP 800-207 deliberately defines zero trust by basic tenets rather than by exclusion, and acknowledges that not every tenet will be fully implemented in its purest form.
Source: NIST SP 800-207 (NIST) — SP 800-207 > 2.1 Tenets of Zero Trust