Zero Trust Implementation Module 6 · Making It Stick

The Rollout Plan

Last reviewed · content updated

Intermediate

What you'll learn

~20 min
  • Assemble the training's mechanisms into a quarterly, maturity-scored roadmap
  • Run the exception register and the metrics that survive audits and leadership changes
  • Close the loop: where the program goes after target state, including procurement

Assembling Meridian

Twenty lessons of mechanisms; one plan to run them. This closing lesson does three things: sequences the whole training onto a calendar, installs the governance that keeps it moving when attention moves on, and answers “what does done mean?” honestly.

The roadmap, assembled from everything and scored the way Lesson 1.3 promised:

Q1 IDENTITY + PILOT CA baseline enforced (2.1) · admins phishing-
resistant (2.2) · JIT for tier-0 (2.3) · group
layer cutover (6.1) · dispatch protect-surface
pilot end-to-end · scorecard: Identity → Advanced
BUYS: for every enrolled admin, a phished password
no longer works; privileged access expires by itself
Q2 DEVICES + MACHINES EDR→MDM→IdP loop enforced per dept (3.1) · OAuth/
agent governance (2.4) · secret triage eliminate-
wave (6.3) · logging centralized, alerts witnessed
(5.1) · scorecard: Devices → Advanced, x-cutting
Visibility → Advanced
BUYS: for every enrolled device, unmanaged or infected
means denied; every alert has reached a human once
Q3 NETWORKS per-app migration waves (3.2) · flow mapping →
first default-deny tiers (3.3) · OT enclave +
brokered access (3.4) · detections-as-code repo
live (5.2) · scorecard: Networks → Initial+
BUYS: on the migrated apps, a breached workstation
cannot roam; plant systems reachable only through
the broker
Q4 DATA + PROOF labels + auto-labeling (4.2) · washroom at the
boundary (4.1) · CAE coverage map + fixes (4.3) ·
denial matrix full suite (5.3) · five-value grade
published (5.2) · scorecard: Data → Initial+,
program reports YEAR-OVER-YEAR stage movement
BUYS: labeled data protected on the covered services;
every published control claim backed by evidence

Legend: scorecard stages are CISA ZTMM’s (Traditional / Initial / Advanced / Optimal); “Initial+” is Meridian shorthand for Initial achieved with Advanced work underway, each stage claim backed by the quarter’s evidence · CA = Conditional Access policy (who may sign in, from what, under which conditions) · JIT = time-boxed admin rights · tier-0 = the accounts that control everything else · EDR→MDM→IdP = endpoint security feeds device management feeds sign-in, so device health gates access · OT = plant and building control systems · CAE = sessions revoked mid-session when risk changes · washroom = the file-sanitizing boundary from 4.1 · x-cutting = the cross-cutting maturity pillars.

Each quarter ends the same way: the ZTMM scorecard re-run, stage claims backed by evidence (a witnessed alert, a passing denial matrix, a grade table), and next quarter re-planned from what the scorecard says — not from what the original roadmap hoped. Each quarter buys a specific, reportable reduction in exposure — the BUYS lines — and the scorecard is how you show the board the money moved a number before deciding what next quarter’s money should move. The roadmap is a hypothesis; the scorecard is the experiment.

The governance rails

The exception register is the program’s immune system. Every “not yet” this training generated — the legacy app that can’t do device policy (3.2), the OT gear that can’t do identity (3.4), the SaaS that ignores revocation (4.3), the scattered workspace pending migration (5.1) — lives in ONE register: control, gap, compensating control, owner, expiry, review date. The rules that keep it honest: no permanent entries (an exception without an expiry is a policy change wearing a disguise — Lesson 1.3’s rule, now with a home); expiries page owners; and the register is reported, not hidden — its length and age are program metrics. A shrinking register is Zero Trust happening; a growing one is the architecture quietly repealing itself, visible early.

The metrics that survive. CISOs change, budgets wobble, auditors rotate. The numbers that keep meaning through all of it, one per pillar-ish concern, each mechanically producible:

- ZTMM stage per pillar (quarterly, evidence-linked) - the strategic one
- % apps under per-app policy / off the VPN scope - 3.2's migration
- % identities with NO standing privilege - humans AND machines
- % fleet compliant + median detection→block latency - 3.1's loop, timed
- denial-matrix pass rate + regressions caught - 5.3, the proof
- exception register: count, median age, expired-overdue - the honesty gauge

Where the evidence goes. Federal readers: these artifacts — control-tagged alerts (5.1), five-value grades with citations (5.2), witnessed firings, denial-matrix results — are precisely the machine-verifiable evidence the modern accreditation and cloud-authorization regimes are moving toward (continuous authorization programs, machine-readable assessment packages). Build the pipeline once; feed compliance forever — the catalog-and-collectors build is the Cloud Modernization training’s closing lesson, and it composes with everything here. Commercial readers get the same artifacts with different consumers: customer security reviews, cyber-insurance questionnaires, board reporting.

Procurement is a control surface too. Every future RFP inherits the architecture: vendors must support your federation (no local passwords — 2.4), device posture claims where relevant (3.1), revocation events or short tokens (4.3), and export their logs to your pipeline (5.1). The cheapest Zero Trust control is the incompatible product you never bought — and modern cloud-authorization marketplaces increasingly let you check assurance claims before the demo, not after the contract.

What “done” means, honestly

Set the expectation the industry’s own numbers set: mature, measurable Zero Trust programs remain a minority of enterprises; the federal benchmark rollout — the largest ever attempted — runs on a multi-year clock toward its target level with formally validated early finishers as existence proofs, not averages. Meridian’s year gets it to defensible-and-improving, not “done”: the scorecard mostly Advanced, the register shrinking, the metrics trending — and the loop (tenet 7) running permanently, because the estate, the threats, and the guidance (Lesson 1.2’s quarterly currency check — keep it) never stop moving. Zero Trust is an operating model that survives its own champions. That’s the design goal, and everything in this training — mechanisms that are structural rather than heroic, evidence that is generated rather than assembled, exceptions that expire rather than accrete — was chosen so the program outlives the people who launched it. Your turn: run the Lesson 1.1 flow-mapping on your own estate, score it against the ZTMM, and start where every real program starts — identity, with a pilot you can finish.

KNOWLEDGE CHECK

Eighteen months in, a new CISO arrives mid-budget-cut and asks: 'Show me whether this Zero Trust program is real or theater — you have one meeting.' Which artifact set answers, and why does it work on someone with no context?

Practice status — among mature regulated delivery programs, commercial and federal

(a few rows carry a more specific status - principle, canon, suspended - where one of the five would mislead)

PracticeStatusAlso called
quarterly maturity-scored roadmapcommon baselinematurity-model roadmap (CISA ZTMM here)
identity-first sequencingcommon baseline the order every major ZT program converged on—
expiring exception registerstrong optional (commercial); federal programs pair it with the required POA&M (Plan of Action and Milestones) - related, not the same: the POA&M tracks remediation plans; the register records accepted risk with an owner and an expiry—
protect-surface pilotcommon baselinethin-slice / lighthouse pilot
mechanical program metricsstrong optional metrics that survive leadership turnover—

Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging

Key takeaway

Four quarters, each ending in an evidence-backed scorecard; one exception register with expiries that page; metrics a skeptic can regenerate; procurement enforcing the architecture at the front door; and the honest definition of done — defensible, improving, and running as an operating model rather than a project. Meridian is fictional; the mechanisms are not. Map your flows, score your pillars, and go start Quarter 1.

LEADERSHIP DECISION fund by quarter against the BUYS line, renew on
scorecard movement, and sign the exception register's
expiries (or route them to the AO - the authorizing
official who signs risk acceptance - where a federal
authorization is in play)
PRACTITIONER ACTION sequence identity → devices → networks → data, re-run
the ZTMM scorecard each quarter with evidence, keep
exceptions owned and expiring
SUCCESS MEASURE evidenced maturity stage movement per pillar each year;
exception debt trending to zero by expiry date; zero
unowned exceptions found at audit
Search lessons