Siam Thanat Hack Co., Ltd.

NCSA Zero Trust Guidelines

A source-based guide to NCSA's Zero Trust Guidelines, published as version 1.0, for executives, policy owners, technical teams, system administrators, and security engineers planning a risk-based transition from perimeter security to continuous verification.

Zero Trust principles and adoption scope

The guidance shifts the assumption from trusting an internal network to verifying every access request against identity, device posture, and session context.

Thai infographic explaining: Zero Trust principles and adoption scope
Visual guide: Zero Trust principles and adoption scope
  • All resources, including data, applications, services, and devices, should be treated as assets that need protection regardless of where they reside.
  • Access should be granted per session and adjusted to risk using relevant evidence such as identity, device posture, location, and behavior.
  • The seven Zero Trust principles emphasize strict authentication and authorization, continuous security monitoring of assets, and using collected information to improve controls.

Architecture and policy decision points

The document explains that requesters and their devices pass through policy decision points before they can reach a resource, separating decision, session-management, and enforcement responsibilities.

Thai infographic explaining: Architecture and policy decision points
Visual guide: Architecture and policy decision points
  • The Policy Engine evaluates policy and supporting information to decide whether access is permitted.
  • The Policy Administrator establishes or terminates communication paths and manages session credentials according to that decision.
  • The Policy Enforcement Point opens, monitors, or terminates connections and should draw on identity, device, security telemetry, and other relevant information sources.

A five-step risk-based transition

The guidance starts with a defined protect surface and expands incrementally instead of changing every system at once.

Thai infographic explaining: A five-step risk-based transition
Visual guide: A five-step risk-based transition
  • Define the Protect Surface and a risk-based strategy, then map Transaction Flows to understand the relationship among data, applications, assets, and services.
  • Design the Zero Trust architecture for that surface, considering identity, segmentation, microsegmentation, cloud, or hybrid approaches according to context and risk.
  • Define policy through the 5W1H framework: Who, What, When, Where, Why, and How. Then monitor, log, alert, and continually review protect surfaces and policy.

Gap analysis, maturity, and continuous operations

Gap analysis needs to cover strategy, governance, data, assets, operations, and control effectiveness rather than comparing tool inventories alone.

Thai infographic explaining: Gap analysis, maturity, and continuous operations
Visual guide: Gap analysis, maturity, and continuous operations
  • Use the Risk Management Framework to structure the gap analysis across preparation, categorization, control selection, assessment, authorization, and monitoring.
  • Use the Zero Trust Maturity Model to assess the five pillars of identity, devices, networks, applications and workloads, and data, with connected risk indicators.
  • Establish roles, accountability, communication, training, and feedback loops so policy can adapt to incidents and changing environments.

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofNCSA Zero Trust Guidelines

NCSA Zero Trust Guidelines

By NCSA

Open document (PDF) Source