International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1720160

1720160 Vol 10 · Issue 1 Download Paper

Zero-Trust Security Architecture for Cloud Computing and Enterprise IT Systems: Principles, Design, and Implementation Challenges

Darshankumar Jaysukh Dhanani

Subject area: Science,Engineering and Technology  ·  Area of research: Cloud Computing and Enterprise

DOI: https://doi.org/10.64388/IREV10I1-1720160

Abstract

The castle-and-moat security model that has long been the backbone of enterprise security has been undermined with enterprise workloads moving to public, private and hybrid cloud. To meet this change, there is a new way to securely and reliably manage access to resources: zero-trust architecture (ZTA), which assumes that every access request is a potential threat and continuously verifies identity, device posture and contextual risk before allowing least privilege access to resources on a session-by-session basis. This article reviews the literature on zero-trust security for cloud computing and enterprise information technology (IT) environments and synthesizes the information into an integrative literature review and architecture synthesis. The article follows a structured narrative-synthesis approach and is based on the National Institute of Standards and Technology (NIST) SP 800-207 model and 21 peer-reviewed and standards-based sources, which are used to build a logical zero-trust architecture, a blueprint for a multi-cloud deployment, and a zero-trust versus perimeter-based security comparison across key operational metrics. Challenges to adoption, such as legacy-system integration, policy complexity and organisational readiness are discussed and directions for future research, in particular integration of AI in continuous risk scoring are outlined. The results show that while the adoption of a zero-trust approach requires significant architectural and cultural adjustments, it has significant results in reducing the lateral movement, exposure to insider threats and impact of a breach when compared to traditional perimeter defenses.

Keywords

Zero-Trust Model, Cloud Security, Enterprise IT, Identity and Access Management, Microsegmentation, NIST SP 800-207 And Cybersecurity Architecture.

How to cite this paper

Darshankumar Jaysukh Dhanani "Zero-Trust Security Architecture for Cloud Computing and Enterprise IT Systems: Principles, Design, and Implementation Challenges" Iconic Research And Engineering Journals, vol. 10, no. 1, Jul. 2026, doi: https://doi.org/10.64388/IREV10I1-1720160
Darshankumar Jaysukh Dhanani (2026). Zero-Trust Security Architecture for Cloud Computing and Enterprise IT Systems: Principles, Design, and Implementation Challenges. Iconic Research And Engineering Journals, 10(1). doi: https://doi.org/10.64388/IREV10I1-1720160
Darshankumar Jaysukh Dhanani "Zero-Trust Security Architecture for Cloud Computing and Enterprise IT Systems: Principles, Design, and Implementation Challenges" Iconic Research And Engineering Journals, vol. 10, no. 1, Jul. 2026. Crossref, https://doi.org/10.64388/IREV10I1-1720160
@article{1720160,
      author = {Darshankumar Jaysukh Dhanani},
      title = {Zero-Trust Security Architecture for Cloud Computing and Enterprise IT Systems: Principles, Design, and Implementation Challenges},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {1},
      pages = {2983-2994},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1720160.pdf},
      abstract = {The castle-and-moat security model that has long been the backbone of enterprise security has been undermined with enterprise workloads moving to public, private and hybrid cloud. To meet this change, there is a new way to securely and reliably manage access to resources: zero-trust architecture (ZTA), which assumes that every access request is a potential threat and continuously verifies identity, device posture and contextual risk before allowing least privilege access to resources on a session-by-session basis. This article reviews the literature on zero-trust security for cloud computing and enterprise information technology (IT) environments and synthesizes the information into an integrative literature review and architecture synthesis. The article follows a structured narrative-synthesis approach and is based on the National Institute of Standards and Technology (NIST) SP 800-207 model and 21 peer-reviewed and standards-based sources, which are used to build a logical zero-trust architecture, a blueprint for a multi-cloud deployment, and a zero-trust versus perimeter-based security comparison across key operational metrics. Challenges to adoption, such as legacy-system integration, policy complexity and organisational readiness are discussed and directions for future research, in particular integration of AI in continuous risk scoring are outlined. The results show that while the adoption of a zero-trust approach requires significant architectural and cultural adjustments, it has significant results in reducing the lateral movement, exposure to insider threats and impact of a breach when compared to traditional perimeter defenses.},
      keywords = {Zero-Trust Model, Cloud Security, Enterprise IT, Identity and Access Management, Microsegmentation, NIST SP 800-207 And Cybersecurity Architecture.},
      month = {July},
      doi = {https://doi.org/10.64388/IREV10I1-1720160}
  }