{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T13:12:49Z","timestamp":1778159569366,"version":"3.51.4"},"reference-count":22,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2022,8,31]],"date-time":"2022-08-31T00:00:00Z","timestamp":1661904000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2022,8,31]]},"abstract":"<jats:p>Changing network landscapes and rising security threats have imparted a sense of urgency for new approaches to security. Zero trust has been proposed as a solution to these problems, but some regard it as a marketing tool to sell existing best practice while others praise it as a new cybersecurity standard. This article discusses the history and development of zero trust and why the changing threat landscape has led to a new discourse in cybersecurity. Drivers, barriers, and business implications of zero trust provide a backdrop for a brief overview of key logical components of a zero trust architecture and implementation challenges.<\/jats:p>","DOI":"10.1145\/3561799","type":"journal-article","created":{"date-parts":[[2022,9,19]],"date-time":"2022-09-19T22:14:42Z","timestamp":1663625682000},"page":"80-106","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["From Zero to One Hundred"],"prefix":"10.1145","volume":"20","author":[{"given":"Matthew","family":"Bush","sequence":"first","affiliation":[{"name":"Toronto Metropolitan University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Atefeh","family":"Mashatan","sequence":"additional","affiliation":[{"name":"Ted Rogers School of Information Technology Management"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,9,19]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1016\/S2212-5671(15)01077-1"},{"key":"e_1_2_1_2_1","unstructured":"Beske C. M. Peck J. Saltonstall M. 2017. Migrating to BeyondCorp: maintaining productivity while improving security. Login 42 (2). Google Research; https:\/\/research.google\/pubs\/pub46134\/."},{"key":"e_1_2_1_3_1","unstructured":"Bleech N. 2005. What is Jericho Forum? Visioning White Paper Jericho Forum; https:\/\/collaboration.opengroup.org\/jericho\/vision_wp.pdf."},{"key":"e_1_2_1_4_1","volume-title":"Annual Cybersecurity Report","author":"Cisco","year":"2018","unstructured":"Cisco. 2018. Annual Cybersecurity Report, vol. 8, p. 19; https:\/\/www.cisco.com\/c\/dam\/m\/hu_hu\/campaigns\/security-hub\/pdf\/acr-2018.pdf."},{"key":"e_1_2_1_5_1","unstructured":"Cunningham C. Pollard J. Holmes D. 2019. The eight business and security benefits of zero trust. Forrester; https:\/\/www.forrester.com\/report\/The-Eight-Business-And-Security-Benefits-Of-Zero-Trust\/RES134863."},{"key":"e_1_2_1_6_1","unstructured":"Cunningham C. 2019. The Zero Trust eXtended (ZTX) ecosystem. Forrester."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","unstructured":"Embrey B. 2020. The top three factors driving zero trust adoption. Computer Fraud & Security 2020 (9) 13?15; https:\/\/doi.org\/10.1016\/S1361-3723(20)30097-X.","DOI":"10.1016\/S1361-3723(20)30097-X"},{"key":"e_1_2_1_8_1","unstructured":"FireEye. 2019. M-Trends 2019; https:\/\/content.fireeye.com\/m-trends\/rpt-m-trends-2019."},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Garbis J. Chapman J. W. 2021. Zero Trust Security 1st edition. Apress.","DOI":"10.1007\/978-1-4842-6702-8"},{"key":"e_1_2_1_10_1","unstructured":"Jericho Forum. 2007. Jericho Forum Commandments; https:\/\/collaboration.opengroup.org\/jericho\/commandments_v1.2.pdf."},{"key":"e_1_2_1_11_1","unstructured":"Kindervag J. Balaouras S. Coit L. 2010. Build security into your network's DNA: the zero trust network architecture 1?26. Forrester; https:\/\/www.virtualstarmedia.com\/downloads\/Forrester_zero_trust_DNA.pdf."},{"key":"e_1_2_1_12_1","unstructured":"Kindervag J. Balaouras S. Coit L. 2010. No more chewy centers: introducing the zero trust model of information security. Forrester; https:\/\/media.paloaltonetworks.com\/documents\/Forrester-No-More-Chewy-Centers.pdf."},{"key":"e_1_2_1_13_1","unstructured":"Kindervag J. Mak K. 2015. Case study: WestJet redefines its security with Forrester's zero trust model. Forrester; https:\/\/www.forrester.com\/report\/case-study-westjet-redefines-its-security-with-forrester-s-zero-trust-model\/RES122205?objectid=RES122205."},{"key":"e_1_2_1_14_1","volume-title":"Applied Organizational Change in Industry: Structural, Technological and Humanistic Approaches","author":"Leavitt H. J.","unstructured":"Leavitt, H. J., March, J. G. 1962. Applied Organizational Change in Industry: Structural, Technological and Humanistic Approaches. Carnegie Institute of Technology, Graduate School of Industrial Administration; https:\/\/books.google.ca\/books?id=P_KZNQAACAAJ."},{"key":"e_1_2_1_15_1","unstructured":"National Cybersecurity Centre. 2020. Mobile device guidance: network architectures; https:\/\/www.ncsc.gov.uk\/collection\/mobile-device-guidance\/infrastructure\/network-architectures-for-remote-access."},{"key":"e_1_2_1_16_1","volume-title":"Zero trust and 5G?realizing zero trust in networks. Ericsson Technology Review #05","author":"Olsson J.","year":"2021","unstructured":"Olsson, J., Shorov, A., Abdelrazek, L., Whitefield, J. 2021. Zero trust and 5G?realizing zero trust in networks. Ericsson Technology Review #05; https:\/\/www.ericsson.com\/49a20a\/assets\/local\/reports-papers\/ericsson-technology-review\/docs\/2021\/zero-trust-and-5g.pdf."},{"key":"e_1_2_1_17_1","volume-title":"Five key considerations when adopting a zero trust security architecture. @ISACA 7","author":"Pironti J. P.","year":"2020","unstructured":"Pironti, J. P. 2020. Five key considerations when adopting a zero trust security architecture. @ISACA 7; https:\/\/www.isaca.org\/resources\/news-and-trends\/newsletters\/atisaca\/2020\/volume-7\/five-key-considerations-when-adopting-a-Zero Trust-security-architecture."},{"key":"e_1_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Rose S. Borchert O. Mitchell S. Connelly S. 2020. Zero trust architecture NIST SP 800-207; https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-207\/final.","DOI":"10.6028\/NIST.SP.800-207"},{"key":"e_1_2_1_19_1","volume-title":"process, and technology. Schneier on Security","author":"Schneier B.","year":"2013","unstructured":"Schneier, B. 2013. People, process, and technology. Schneier on Security; https:\/\/www.schneier.com\/blog\/archives\/2013\/01\/people_process.html."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(21)00019-2"},{"key":"e_1_2_1_21_1","unstructured":"United Kingdom National Cyber Security Centre. Zero-trust-architecture. Github; https:\/\/github.com\/ukncsc\/zero-trust-architecture."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-8083-3_5"}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3561799","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3561799","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:02:24Z","timestamp":1750186944000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3561799"}},"subtitle":["Demystifying zero trust and its implications on enterprise people, process, and technology"],"short-title":[],"issued":{"date-parts":[[2022,8,31]]},"references-count":22,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,8,31]]}},"alternative-id":["10.1145\/3561799"],"URL":"https:\/\/doi.org\/10.1145\/3561799","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"value":"1542-7730","type":"print"},{"value":"1542-7749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,8,31]]},"assertion":[{"value":"2022-09-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}