Zero Trust (Maritime)
E3. Technology, digitalization and smart shippingDefinition
Cyber model requiring verification of every device/user.
Zero trust is a security model that grants no implicit trust based on network location and instead verifies every device, user, and request before access, enforcing least privilege and continuous authentication. NIST SP 800-207 (August 2020) defines its architecture. Applied to ships, it counters the flat-network assumption behind many OT incidents by segmenting IT from OT, authenticating remote-maintenance sessions, and gating each control-system connection, reinforcing the network-protection and access-control requirements of IACS UR E26 and E27.
Source: NIST SP 800-207, Zero Trust Architecture, August 2020