The Rollout Plan
Last reviewed · content updated
IntermediateWhat you'll learn
~20 min- Assemble the training's mechanisms into a quarterly, maturity-scored roadmap
- Run the exception register and the metrics that survive audits and leadership changes
- Close the loop: where the program goes after target state, including procurement
Assembling Meridian
Twenty lessons of mechanisms; one plan to run them. This closing lesson does three things: sequences the whole training onto a calendar, installs the governance that keeps it moving when attention moves on, and answers “what does done mean?” honestly.
The roadmap, assembled from everything and scored the way Lesson 1.3 promised:
Q1 IDENTITY + PILOT CA baseline enforced (2.1) · admins phishing- resistant (2.2) · JIT for tier-0 (2.3) · group layer cutover (6.1) · dispatch protect-surface pilot end-to-end · scorecard: Identity → Advanced BUYS: for every enrolled admin, a phished password no longer works; privileged access expires by itselfQ2 DEVICES + MACHINES EDR→MDM→IdP loop enforced per dept (3.1) · OAuth/ agent governance (2.4) · secret triage eliminate- wave (6.3) · logging centralized, alerts witnessed (5.1) · scorecard: Devices → Advanced, x-cutting Visibility → Advanced BUYS: for every enrolled device, unmanaged or infected means denied; every alert has reached a human onceQ3 NETWORKS per-app migration waves (3.2) · flow mapping → first default-deny tiers (3.3) · OT enclave + brokered access (3.4) · detections-as-code repo live (5.2) · scorecard: Networks → Initial+ BUYS: on the migrated apps, a breached workstation cannot roam; plant systems reachable only through the brokerQ4 DATA + PROOF labels + auto-labeling (4.2) · washroom at the boundary (4.1) · CAE coverage map + fixes (4.3) · denial matrix full suite (5.3) · five-value grade published (5.2) · scorecard: Data → Initial+, program reports YEAR-OVER-YEAR stage movement BUYS: labeled data protected on the covered services; every published control claim backed by evidenceLegend: scorecard stages are CISA ZTMM’s (Traditional / Initial / Advanced / Optimal); “Initial+” is Meridian shorthand for Initial achieved with Advanced work underway, each stage claim backed by the quarter’s evidence · CA = Conditional Access policy (who may sign in, from what, under which conditions) · JIT = time-boxed admin rights · tier-0 = the accounts that control everything else · EDR→MDM→IdP = endpoint security feeds device management feeds sign-in, so device health gates access · OT = plant and building control systems · CAE = sessions revoked mid-session when risk changes · washroom = the file-sanitizing boundary from 4.1 · x-cutting = the cross-cutting maturity pillars.
Each quarter ends the same way: the ZTMM scorecard re-run, stage claims backed by evidence (a witnessed alert, a passing denial matrix, a grade table), and next quarter re-planned from what the scorecard says — not from what the original roadmap hoped. Each quarter buys a specific, reportable reduction in exposure — the BUYS lines — and the scorecard is how you show the board the money moved a number before deciding what next quarter’s money should move. The roadmap is a hypothesis; the scorecard is the experiment.
The governance rails
The exception register is the program’s immune system. Every “not yet” this training generated — the legacy app that can’t do device policy (3.2), the OT gear that can’t do identity (3.4), the SaaS that ignores revocation (4.3), the scattered workspace pending migration (5.1) — lives in ONE register: control, gap, compensating control, owner, expiry, review date. The rules that keep it honest: no permanent entries (an exception without an expiry is a policy change wearing a disguise — Lesson 1.3’s rule, now with a home); expiries page owners; and the register is reported, not hidden — its length and age are program metrics. A shrinking register is Zero Trust happening; a growing one is the architecture quietly repealing itself, visible early.
The metrics that survive. CISOs change, budgets wobble, auditors rotate. The numbers that keep meaning through all of it, one per pillar-ish concern, each mechanically producible:
- ZTMM stage per pillar (quarterly, evidence-linked) - the strategic one- % apps under per-app policy / off the VPN scope - 3.2's migration- % identities with NO standing privilege - humans AND machines- % fleet compliant + median detection→block latency - 3.1's loop, timed- denial-matrix pass rate + regressions caught - 5.3, the proof- exception register: count, median age, expired-overdue - the honesty gaugeWhere the evidence goes. Federal readers: these artifacts — control-tagged alerts (5.1), five-value grades with citations (5.2), witnessed firings, denial-matrix results — are precisely the machine-verifiable evidence the modern accreditation and cloud-authorization regimes are moving toward (continuous authorization programs, machine-readable assessment packages). Build the pipeline once; feed compliance forever — the catalog-and-collectors build is the Cloud Modernization training’s closing lesson, and it composes with everything here. Commercial readers get the same artifacts with different consumers: customer security reviews, cyber-insurance questionnaires, board reporting.
Procurement is a control surface too. Every future RFP inherits the architecture: vendors must support your federation (no local passwords — 2.4), device posture claims where relevant (3.1), revocation events or short tokens (4.3), and export their logs to your pipeline (5.1). The cheapest Zero Trust control is the incompatible product you never bought — and modern cloud-authorization marketplaces increasingly let you check assurance claims before the demo, not after the contract.
What “done” means, honestly
Set the expectation the industry’s own numbers set: mature, measurable Zero Trust programs remain a minority of enterprises; the federal benchmark rollout — the largest ever attempted — runs on a multi-year clock toward its target level with formally validated early finishers as existence proofs, not averages. Meridian’s year gets it to defensible-and-improving, not “done”: the scorecard mostly Advanced, the register shrinking, the metrics trending — and the loop (tenet 7) running permanently, because the estate, the threats, and the guidance (Lesson 1.2’s quarterly currency check — keep it) never stop moving. Zero Trust is an operating model that survives its own champions. That’s the design goal, and everything in this training — mechanisms that are structural rather than heroic, evidence that is generated rather than assembled, exceptions that expire rather than accrete — was chosen so the program outlives the people who launched it. Your turn: run the Lesson 1.1 flow-mapping on your own estate, score it against the ZTMM, and start where every real program starts — identity, with a pilot you can finish.
Eighteen months in, a new CISO arrives mid-budget-cut and asks: 'Show me whether this Zero Trust program is real or theater — you have one meeting.' Which artifact set answers, and why does it work on someone with no context?
Practice status — among mature regulated delivery programs, commercial and federal
(a few rows carry a more specific status - principle, canon, suspended - where one of the five would mislead)
| Practice | Status | Also called |
|---|---|---|
| quarterly maturity-scored roadmap | common baseline | maturity-model roadmap (CISA ZTMM here) |
| identity-first sequencing | common baseline the order every major ZT program converged on | — |
| expiring exception register | strong optional (commercial); federal programs pair it with the required POA&M (Plan of Action and Milestones) - related, not the same: the POA&M tracks remediation plans; the register records accepted risk with an owner and an expiry | — |
| protect-surface pilot | common baseline | thin-slice / lighthouse pilot |
| mechanical program metrics | strong optional metrics that survive leadership turnover | — |
Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging
Key takeaway
Four quarters, each ending in an evidence-backed scorecard; one exception register with expiries that page; metrics a skeptic can regenerate; procurement enforcing the architecture at the front door; and the honest definition of done — defensible, improving, and running as an operating model rather than a project. Meridian is fictional; the mechanisms are not. Map your flows, score your pillars, and go start Quarter 1.
LEADERSHIP DECISION fund by quarter against the BUYS line, renew on scorecard movement, and sign the exception register's expiries (or route them to the AO - the authorizing official who signs risk acceptance - where a federal authorization is in play)PRACTITIONER ACTION sequence identity → devices → networks → data, re-run the ZTMM scorecard each quarter with evidence, keep exceptions owned and expiringSUCCESS MEASURE evidenced maturity stage movement per pillar each year; exception debt trending to zero by expiry date; zero unowned exceptions found at audit