Home / Current Issue / Paper 1718630
Zero Trust Architecture in Corporate Networks: Reduced VPN Dependence, Threat Containment, and Access Governance in Hybrid Environments
Subject area: Science,Engineering and Technology · Area of research: Sciences
DOI: 10.64388/IREV8I10-1718630
Abstract
Zero Trust Architecture has been proposed as a structural response to the erosion of perimeter‑based security in corporate networks characterized by remote work, cloud migration, heterogeneous endpoints, and the rising frequency of ransomware and lateral‑movement attacks. Unlike the traditional perimeter‑centric model, Zero Trust assumes that no user, device, or session should be trusted by default, even when the connection originates from an apparently internal environment. This article discusses, based on scientific literature and a major technical reference document, the conceptual foundations of Zero Trust, its relationship with Zero Trust Network Access (ZTNA), its differences from legacy VPN models, and its implications for access control, operational performance, and regulatory alignment. The analysis indicates that contextual policies, strict enforcement of least privilege, logical segmentation, and continuous verification can reduce unnecessary exposure to corporate resources while improving threat containment without necessarily increasing operational friction. The paper concludes that Zero Trust should not be understood merely as a tightening of controls, but as an architectural reorganization of security around identity, context, and continuous resource protection.
Keywords
Zero Trust, ZTNA, VPN, Network Security, Access Control.
References
[1] Rose S, Borchert O, Mitchell S, Connelly S. Zero trust architecture. Gaithersburg: National Institute of Standards and Technology; 2020. doi:10.6028/NIST.SP.800-207.
[2] Syed NF, Shah SW, Shaghaghi A, Anwar A, Baig Z, Doss R. Zero trust architecture (ZTA): a comprehensive survey. IEEE Access. 2022;10:57143‑57179. doi:10.1109/ACCESS.2022.3174679.
[3] Sarkar S, Choudhary G, Shandilya SK, Hussain A, Kim H. Security of zero trust networks in cloud computing: a comparative review. Sustainability. 2022;14(18):11213. doi:10.3390/su141811213.
[4] Zohaib SM, Sajjad S, Iqbal Z, Yousaf M, Haseeb M, Muhammad Z. Zero trust VPN (ZT‑VPN): a systematic literature review and cybersecurity framework for hybrid and remote work. Information. 2024;15(11):734. doi:10.3390/info15110734.
[5] Cao Y, Pokhrel S, Zhu Y, Doss R, Li G. Automation and orchestration of zero trust architecture: potential solutions and challenges. Mach Intell Res. 2024;21:294‑317. doi:10.1007/s11633‑023‑1456‑2.
[6] Nahar N, Andersson K, Schelén O, Saguna S. A survey on zero trust architecture: applications and challenges of 6G networks. IEEE Access. 2024;12:94753‑94764. doi:10.1109/ACCESS.2024.3425350.
[7] Ruambo FA, Masanga EE, Lufyagila B, Ateya AA, Almousa M, Abd-El-Atty B. Brute‑force attack mitigation on remote access services via software‑defined perimeter. Sci Rep. 2025;15(1):18599. doi:10.1038/s41598‑025‑01080‑5.
[8] Gambo ML, Almulhem A. Zero trust architecture: a systematic literature review. J Netw Syst Manage. 2025. doi:10.1007/s10922‑025‑09998‑x.
[9] Pourre, C. B. F. (2024). UMA ANÁLISE BIBLIOMÉTRICA DA PESQUISA DE FRAMEWORK DE CIDADES INTELIGENTES. Revista Sistemática, 14(8), 591–605. https://doi.org/10.56238/rcsv14n8-00926.
[10] [1:19 PM, 19/05/2026] Carlla Furlan Pourre: POURRE, C. B. F. Indicadores de resultados finalísticos como instrumento de diagnóstico do transporte urbano: um estudo de caso do Distrito Federal. 2020. Dissertação (Mestrado em Arquitetura e Urbanismo) – Universidade Federal de Brasília, Brasília, 2020. Disponível em: https://repositorio.unb.br/handle/10482/38743. Acesso em: 23 out. 2025.
[11] Carlla Furlan Pourre: FURLAN, Carlla Brito; SANTOS, Gleys Ially Ramos dos. 2016. A qualidade do transporte público urbano em cidades médias: estudo de caso em Palmas-Tocantins. Revista em Gestão, Inovação e Sustentabilidade. Disponível em: chrome-extension://efaidnbmnnMarecilda; Mello, Cristina de. 2022.
[12] Gotardi Pessoa, E. (2025). Analysis of the performance of helical piles under various load and geometry conditions. ITEGAM-JETIA, 11(53), 135-140. https://doi.org/10.5935/jetia.v11i53.1887
[13] Gotardi Pessoa, E. (2025). Sustainable solutions for urban infrastructure: The environmental and economic benefits of using recycled construction and demolition waste in permeable pavements. ITEGAM-JETIA, 11(53), 131-134. https://doi.org/10.5935/jetia.v11i53.1886
How to cite this paper
@article{1718630,
author = {Valdir de Espíndula},
title = {Zero Trust Architecture in Corporate Networks: Reduced VPN Dependence, Threat Containment, and Access Governance in Hybrid Environments},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {8},
number = {10},
pages = {1930-1933},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1718630.pdf},
abstract = {Zero Trust Architecture has been proposed as a structural response to the erosion of perimeter‑based security in corporate networks characterized by remote work, cloud migration, heterogeneous endpoints, and the rising frequency of ransomware and lateral‑movement attacks. Unlike the traditional perimeter‑centric model, Zero Trust assumes that no user, device, or session should be trusted by default, even when the connection originates from an apparently internal environment. This article discusses, based on scientific literature and a major technical reference document, the conceptual foundations of Zero Trust, its relationship with Zero Trust Network Access (ZTNA), its differences from legacy VPN models, and its implications for access control, operational performance, and regulatory alignment. The analysis indicates that contextual policies, strict enforcement of least privilege, logical segmentation, and continuous verification can reduce unnecessary exposure to corporate resources while improving threat containment without necessarily increasing operational friction. The paper concludes that Zero Trust should not be understood merely as a tightening of controls, but as an architectural reorganization of security around identity, context, and continuous resource protection.},
keywords = {Zero Trust, ZTNA, VPN, Network Security, Access Control.},
month = {April},
doi = {https://doi.org/10.64388/IREV8I10-1718630}
}