Zero Trust Implementation
Implement Zero Trust from the federal guidance up — identity-centric access, device and network policy, content and data controls, evidence-grade visibility, and a rollout that sticks.
6 modules · 21 lessons · ~6.3 hours · Security teams, network engineers, architects
Chapter 2 in the Meridian sequence · 9 live so far · builds on Cloud Modernization Patterns · continues in Modern DevSecOps Foundations
One year after modernizing its estate, the fictional Meridian Utilities has to secure it — and "we have MFA" is not an architecture. Grounded in NIST 800-207, the CISA Zero Trust Maturity Model, and the current federal corpus, this training implements Zero Trust pillar by pillar: policy baselines, device signals, per-app access, content disarm, evidence-grade logging, and a rollout that survives contact with a real organization. Every lesson uses AI CLI tools to do the real work. No prior Meridian knowledge needed — Lesson 1.1 catches you up in two minutes.
The Curriculum
The Architecture
Kill the misconception first
What Zero Trust actually is per NIST 800-207, the federal corpus as a living map, and the shape of a program that survives
Identity
The control plane
The conditional-access baseline as a policy decision point, phishing-resistant authentication, standing privilege, and the machine identities that outnumber people
Devices and Networks
Signals decide, segments contain
The EDR-to-MDM-to-IdP loop, per-app access replacing the perimeter, microsegmentation done in the right order, and the OT estate you cannot patch
Applications and Data
Never trust what arrives
Content disarm and reconstruction with a fail-closed pipeline, data classification as a policy input, and authorization that never stops evaluating
Visibility and Evidence
Prove it, continuously
Logging under the 2026 rules, detections managed like code, honest control grading, and verification by expected denial
Making It Stick
Run-state governance
Groups as the single source of truth, trust anchors you can move, safe paths by construction, and a rollout plan scored against the maturity model
New to AI CLI tools?
This training assumes you can drive an AI CLI (Claude Code, Codex CLI, Antigravity CLI, or Copilot CLI). If that's new, these modules from our AI-Powered Development training are the fastest preparation — most students need only the first one: