Zero Trust Architecture
TL;DR
This paper synthesizes reported evidence on ZTA across three research questions: effectiveness relative to perimeter models, the implementation challenges enterprises face, and the security contribution of individual components.
Abstract
Background: Cloud computing, remote workforces, and Internet of Things (IoT) deployments have eroded the enterprise network perimeter, exposing the limits of security models that grant implicit trust to internal actors. Zero Trust Architecture (ZTA), governed by the principle of "Never Trust, Always Verify," addresses this through continuous verification, least-privilege access, micro-segmentation, and adaptive monitoring. Objectives: This paper synthesizes reported evidence on ZTA across three research questions: effectiveness relative to perimeter models, the implementation challenges enterprises face, and the security contribution of individual components. Methods: A structured literature review was conducted on a predefined corpus of 37 ZTA-related studies. A rubric-based composite model incorporating relevance, methodology quality, recency, and measurability of outcomes characterized each study. All 37 met the appraisal threshold of S >= 3.0, the lowest composite score being 3.55, so the rubric characterized the corpus rather than functioning as an exclusion filter. Results: Reported findings suggest that ZTA can improve breach detection, reduce unauthorized access, and limit attack propagation in specific empirical and simulation contexts. Headline values, including 75% improvement in breach detection, 66.7% reduction in unauthorized access, up to 80% attack-surface reduction, and 100% repulsion of simulated malicious packet injections, are drawn from a limited number of studies and need replication. Implementation barriers include performance overhead in IoT and edge environments, high transition costs, legacy migration complexity, interoperability gaps, and cultural resistance. Conclusions: ZTA is a promising and structurally well-aligned security framework for modern distributed environments, but the strength of evidence varies by component and deployment context.