Syllabus
Unit 1
Introduction to Zero Trust Architecture – Overview of zero trust principles – Importance and benefits of ZTA in modern cybersecurity. NIST SP 800-207 ZTA reference architecture: Policy Engine, Policy Administrator, Policy Enforcement Point. CISA Zero Trust Maturity Model (2023): Identity, Devices, Networks, Applications & Workloads, Data pillars.
Unit 2
Components of Zero Trust Architecture – Core components: identity, devices, networks, applications, and data – Implementing zero trust in identity and access management. AI/ML-based User and Entity Behaviour Analytics (UEBA) for continuous trust evaluation. Non-Human Identity (NHI) management: service accounts, API keys, agent identities securing the 40:1 NHI-to-human ratio. Decentralized Identifiers (DID) and Verifiable Credentials in ZTA
Unit 3
Implementing Zero Trust – Designing and engineering a zero-trust network – Zero Trust Network Access (ZTNA) architecture: agent-based and agentless models, Implementing zero trust access policies – Case studies on successful zero trust implementations . Data security in ZTA: classification, encryption in transit and at rest, DLP. Application security: API gateway controls, service mesh, mTLS. SIEM and SOAR integration for ZTA telemetry and automated response. Case studies: Google BeyondCorp, Microsoft Zero Trust, NIST NCCoE pilot deployments
Unit 4
Zero Trust in Cloud Environments – Cloud security challenges and engineering solutions – Applying zero trust principles to cloud infrastructure. CSA Agentic Trust Framework (ATF) and OWASP Top 10 for Agentic Applications. Multi-agent system security: MAESTRO threat modeling framework
Unit 5
Advanced Topics in Zero Trust – Zero trust for remote workforces – Implementing zero trust in operational technology (OT) environments – Future trends and engineering advancements in zero trust architecture. AI-powered anomaly detection in OT environments. Post-Quantum Cryptography (PQC) in ZTA: NIST PQC standards. ZTA and regulatory compliance: DPDPA (India), EU AI Act, GDPR, HIPAA, SOC 2
Text Books / References
- Cindy Green-Ortiz, Brandon Fowler, David Houck, Hank Hensel, Patrick Lloyd, Andrew McDonald, Jason Frazier. Zero Trust Architecture. Cisco Press. 2024.
- Razi Rais, Christina Morillo, Evan Gilman, Doug Barth. Zero Trust Networks: Building Secure Systems in Untrusted Networks. O’Reilly Media, Incorporated, 2024.
- Zero Trust Enterprise infrastructure, Dzone Magazine, Oct 2023.
- NIST SP 800-207. Zero Trust Architecture. National Institute of Standards and Technology, 2020. https://doi.org/10.6028/NIST.SP.800-207
- CISA. Zero Trust Maturity Model v2.0. Cybersecurity and Infrastructure Security Agency, 2023. https://www.cisa.gov/zero-trust-maturity-model
- Cloud Security Alliance. The Agentic Trust Framework: Zero Trust Governance for AI Agents. CSA, Feb 2026. https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents
Introduction
This course introduces the fundamentals and advanced concepts of Zero Trust Architecture (ZTA) with a focus on modern cybersecurity engineering across enterprise, cloud, and industrial environments. It covers core ZTA principles, identity and access management, network micro-segmentation, software-defined perimeters, and policy enforcement mechanisms, along with cloud-native zero trust strategies and operational technology (OT) security. The course emphasizes the application of zero trust principles to real-world scenarios such as securing remote workforces, implementing least-privilege access controls, deploying zero trust network access (ZTNA) solutions, and architecting resilient security frameworks for critical infrastructure.
Evaluation Pattern
CO-PO Mapping
| CO |
PO1 |
PO2 |
PO3 |
PSO1 |
PSO2 |
PSO3 |
PSO4 |
| CO1 |
|
|
2 |
2 |
|
|
|
| CO2 |
|
|
3 |
3 |
2 |
|
2 |
| CO3 |
2 |
2 |
3 |
3 |
3 |
2 |
|
Evaluation Pattern – 60:40
- MidTermExam – 30%
- Assignment – 20%
- ClassTest – 10%
- Term Project – 40%