แชร์ผ่าน


Zero Trust assessment terminology

Each recommendation in the Zero Trust guidelines includes a rating for three areas: Risk Level, User Impact, and Implementation Cost. The rating uses the rubric in this article.

Risk Level

Risk Level Description
High There's a potential for environment-wide exposure to threats until you mitigate the issue.
Medium There's a potential for moderate exposure to threats until you mitigate the issue.
Low Mitigation is a defense in depth or an operational optimization.

User Impact

User Impact Description
High A large number of nonprivileged users need to take action or get notified about changes.
Medium A subset of nonprivileged users need to take action or get notified about changes.
Low Administrators can take action. Users don't need to get notified.

Implementation Cost

Implementation Cost Description
High Customer IT and Secops teams need to implement programs that require ongoing time or resource commitment from IT teams.
Medium Customer IT and Secops teams need to drive projects.
Low Customer IT and Secops teams need to execute targeted actions.