Home / Current Issue / Paper 1720160
Zero-Trust Security Architecture for Cloud Computing and Enterprise IT Systems: Principles, Design, and Implementation Challenges
Subject area: Science,Engineering and Technology · Area of research: Cloud Computing and Enterprise
DOI: https://doi.org/10.64388/IREV10I1-1720160
Abstract
The castle-and-moat security model that has long been the backbone of enterprise security has been undermined with enterprise workloads moving to public, private and hybrid cloud. To meet this change, there is a new way to securely and reliably manage access to resources: zero-trust architecture (ZTA), which assumes that every access request is a potential threat and continuously verifies identity, device posture and contextual risk before allowing least privilege access to resources on a session-by-session basis. This article reviews the literature on zero-trust security for cloud computing and enterprise information technology (IT) environments and synthesizes the information into an integrative literature review and architecture synthesis. The article follows a structured narrative-synthesis approach and is based on the National Institute of Standards and Technology (NIST) SP 800-207 model and 21 peer-reviewed and standards-based sources, which are used to build a logical zero-trust architecture, a blueprint for a multi-cloud deployment, and a zero-trust versus perimeter-based security comparison across key operational metrics. Challenges to adoption, such as legacy-system integration, policy complexity and organisational readiness are discussed and directions for future research, in particular integration of AI in continuous risk scoring are outlined. The results show that while the adoption of a zero-trust approach requires significant architectural and cultural adjustments, it has significant results in reducing the lateral movement, exposure to insider threats and impact of a breach when compared to traditional perimeter defenses.
Keywords
Zero-Trust Model, Cloud Security, Enterprise IT, Identity and Access Management, Microsegmentation, NIST SP 800-207 And Cybersecurity Architecture.
References
[1] Ahmadi, S. (2024). Zero trust architecture in cloud networks: Application, challenges and future opportunities. Journal of Engineering Research and Reports, 26(2), 215–228. https://doi.org/10.9734/jerr/2024/v26i21083
[2] Ahn, G., Jang, J., Choi, S., & Shin, D. (2024). Improving cyber resilience by integrating the zero trust security model with the MITRE ATT&CK matrix. IEEE Access, 12, 89291–89309. https://doi.org/10.1109/ACCESS.2024.3417182
[3] Ajish, D. (2024). The significance of artificial intelligence in zero trust technologies: A comprehensive review. Journal of Electrical Systems and Information Technology, 11, Article 20. https://doi.org/10.1186/s43067-024-00155-z
[4] Bartakke, J., & Kashyap, D. R. (2024). The usage of clouds in zero-trust security strategy: An evolving paradigm. Journal of Information and Organizational Sciences, 48(1), 1–15. https://doi.org/10.31341/jios.48.1.8
[5] Bobbert, Y., & Scheerder, J. (2022). Zero trust validation: From practice to theory. An empirical research project to improve zero trust implementations. In 2022 IEEE 29th Annual Software Technology Conference (STC) (pp. 93–104). IEEE. https://doi.org/10.1109/STC55697.2022.00021
[6] Buck, C., Olenberger, C., Schweizer, A., Völter, F., & Eymann, T. (2021). Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust. Computers & Security, 110, Article 102436. https://doi.org/10.1016/j.cose.2021.102436
[7] Chen, B., Qiao, S., Zhao, J., Liu, D., Shi, X., Lyu, M., Chen, H., Lu, H., & Zhai, Y. (2021). A security awareness and protection system for 5G smart healthcare based on zero-trust architecture. IEEE Internet of Things Journal, 8(13), 10248–10263. https://doi.org/10.1109/JIOT.2020.3041042
[8] Dhanapala, I., Bharti, S., McGibney, A., & Rea, S. (2024). Toward a performance-based trustworthy edge-cloud continuum. IEEE Access, 12, 99201–99212. https://doi.org/10.1109/ACCESS.2024.3429197
[9] Dhiman, P., Saini, N., Gulzar, Y., Turaev, S., Kaur, A., Nisa, K. U., & Hamid, Y. (2024). A review and comparative analysis of relevant approaches of zero trust network model. Sensors, 24(4), Article 1328. https://doi.org/10.3390/s24041328
[10] Federici, F., Martintoni, D., & Senni, V. (2023). A zero-trust architecture for remote access in industrial IoT infrastructures. Electronics, 12(3), Article 566. https://doi.org/10.3390/electronics12030566
[11] Ferretti, L., Magnanini, F., Andreolini, M., & Colajanni, M. (2021). Survivable zero trust for cloud computing environments. Computers & Security, 110, Article 102419. https://doi.org/10.1016/j.cose.2021.102419
[12] He, Y., Huang, D., Chen, L., Ni, Y., & Ma, X. (2022). A survey on zero trust architecture: Challenges and future trends. Wireless Communications and Mobile Computing, 2022, Article 6476274. https://doi.org/10.1155/2022/6476274
[13] Liu, C., Tan, R., Wu, Y., Feng, Y., Jin, Z., Zhang, F., Liu, Y., & Liu, Q. (2024). Dissecting zero trust: Research landscape and its implementation in IoT. Cybersecurity, 7(1), 1–28. https://doi.org/10.1186/s42400-024-00212-0
[14] Liu, H., Ai, M., Huang, R., Qiu, R., & Li, Y. (2022). Identity authentication for edge devices based on zero-trust architecture. Concurrency and Computation: Practice and Experience, 34(23), Article e7198. https://doi.org/10.1002/cpe.7198
[15] Mandal, S., Khan, D. A., & Jain, S. (2021). Cloud-based zero trust access control policy: An approach to support work-from-home driven by COVID-19 pandemic. New Generation Computing, 39(3–4), 599–622. https://doi.org/10.1007/s00354-021-00130-6
[16] Rodigari, S., O'Shea, D., McCarthy, P., McCarry, M., & McSweeney, S. (2021). Performance analysis of zero-trust multi-cloud. In 2021 IEEE 14th International Conference on Cloud Computing (CLOUD) (pp. 730–732). IEEE. https://doi.org/10.1109/CLOUD53861.2021.00097
[17] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
[18] Sarkar, S., Choudhary, G., Shandilya, S. K., Hussain, A., & Kim, H. (2022). Security of zero trust networks in cloud computing: A comparative review. Sustainability, 14(18), Article 11213. https://doi.org/10.3390/su141811213
[19] Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero trust architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/ACCESS.2022.3174679
[20] Teerakanok, S., Uehara, T., & Inomata, A. (2021). Migrating to zero trust architecture: Reviews and challenges. Security and Communication Networks, 2021, Article 9947347. https://doi.org/10.1155/2021/9947347
[21] Zanasi, C., Russo, S., & Colajanni, M. (2024). Flexible zero trust architecture for the cybersecurity of industrial IoT infrastructures. Ad Hoc Networks, 156, Article 103414. https://doi.org/10.1016/j.adhoc.2024.103414
How to cite this paper
@article{1720160,
author = {Darshankumar Jaysukh Dhanani},
title = {Zero-Trust Security Architecture for Cloud Computing and Enterprise IT Systems: Principles, Design, and Implementation Challenges},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {1},
pages = {2983-2994},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1720160.pdf},
abstract = {The castle-and-moat security model that has long been the backbone of enterprise security has been undermined with enterprise workloads moving to public, private and hybrid cloud. To meet this change, there is a new way to securely and reliably manage access to resources: zero-trust architecture (ZTA), which assumes that every access request is a potential threat and continuously verifies identity, device posture and contextual risk before allowing least privilege access to resources on a session-by-session basis. This article reviews the literature on zero-trust security for cloud computing and enterprise information technology (IT) environments and synthesizes the information into an integrative literature review and architecture synthesis. The article follows a structured narrative-synthesis approach and is based on the National Institute of Standards and Technology (NIST) SP 800-207 model and 21 peer-reviewed and standards-based sources, which are used to build a logical zero-trust architecture, a blueprint for a multi-cloud deployment, and a zero-trust versus perimeter-based security comparison across key operational metrics. Challenges to adoption, such as legacy-system integration, policy complexity and organisational readiness are discussed and directions for future research, in particular integration of AI in continuous risk scoring are outlined. The results show that while the adoption of a zero-trust approach requires significant architectural and cultural adjustments, it has significant results in reducing the lateral movement, exposure to insider threats and impact of a breach when compared to traditional perimeter defenses.},
keywords = {Zero-Trust Model, Cloud Security, Enterprise IT, Identity and Access Management, Microsegmentation, NIST SP 800-207 And Cybersecurity Architecture.},
month = {July},
doi = {https://doi.org/10.64388/IREV10I1-1720160}
}