Zero Trust Architecture Using NIST SP 800-207 Training Course

10 days Cyber Security Certificate on completion
Course codeSD-CS-060
Duration10 days
LevelIntermediate to Advanced
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Perimeter-based security controls do not adequately protect organisations where users work remotely, workloads span cloud and data centre environments, and applications depend on APIs, SaaS platforms and third parties. Security architects and engineering teams need a defensible way to replace implicit network trust with explicit, continuously evaluated access decisions. This course provides a practical route from the principles in NIST SP 800-207 to an architecture that can be prioritised, implemented and measured across a real enterprise environment.

Participants examine the NIST Zero Trust Architecture model in detail: the policy engine, policy administrator, policy enforcement points, data plane and control plane; identity, device, application and workload signals; and the seven tenets of zero trust. They learn to define protect surfaces, map transaction flows, select policy decision inputs, design least-privilege access policies and integrate identity, endpoint, network and telemetry controls. The course also addresses hybrid cloud patterns, microsegmentation, privileged access, encryption, continuous diagnostics and NIST SP 800-53 control alignment.

Instruction combines expert-led architecture sessions with structured design workshops, scenario analysis and hands-on policy exercises using Microsoft Entra ID and network inspection tools. Each participant develops a NIST SP 800-207-aligned Zero Trust Architecture blueprint for a selected business service or organisational case. The final deliverable includes a protect-surface definition, logical architecture, policy decision matrix, phased implementation roadmap, control mapping and measures for evaluating progress.

The course is suited to experienced cyber security professionals who must turn Zero Trust strategy into engineering decisions, implementation requirements and investment cases. Managers gain staff who can distinguish a standards-based architectural programme from a product-led security refresh.

Course objectives

By the end of this course, participants will be able to:

  • Interpret NIST SP 800-207 components, tenets and deployment models for a hybrid enterprise environment
  • Define protect surfaces and map data, application, workload and user transaction flows
  • Design policy decision points and policy enforcement points using the NIST Zero Trust Architecture logical model
  • Construct a policy decision matrix using identity, device posture, workload, network and risk signals
  • Apply least-privilege access patterns to workforce, privileged, application and machine identities
  • Map Zero Trust architectural decisions to relevant NIST SP 800-53 Rev. 5 control families
  • Evaluate microsegmentation, continuous diagnostics and telemetry requirements for a target service
  • Produce a phased Zero Trust Architecture blueprint and implementation roadmap for a business use case

Benefits of attending

For you

  • Build the ability to lead NIST SP 800-207-based architecture discussions with security, infrastructure and business stakeholders
  • Gain a reusable method for converting Zero Trust principles into policy, enforcement and telemetry requirements
  • Strengthen credibility when assessing vendor Zero Trust claims against a recognised NIST reference architecture
  • Create portfolio-ready architecture artefacts including a policy matrix, logical design and implementation roadmap
  • Prepare for senior security architecture responsibilities involving hybrid cloud access and identity-led security controls

For your organisation

  • Establish a common NIST-based language for Zero Trust decisions across security, network, cloud and IAM teams
  • Reduce reliance on implicit network trust by identifying enforceable controls around high-value services and data
  • Improve investment decisions by separating architectural capabilities from individual vendor product claims
  • Produce phased implementation plans that expose dependencies in identity, endpoint posture, telemetry and segmentation
  • Create traceable links between Zero Trust design choices and NIST SP 800-53 control objectives

Target competencies

Zero Trust modellingProtect surface analysisPolicy decision designIdentity-centric accessMicrosegmentation planningControl mapping

Who should attend

  • Security Architects — who must translate Zero Trust principles into enterprise security architecture and target-state designs
  • Cyber Security Architects — who need to specify policy enforcement, telemetry and control integrations across hybrid environments
  • Identity and Access Management Leads — who design conditional access, privileged access and identity assurance policies
  • Network Security Engineers — who implement segmentation and enforcement controls without relying on broad network trust
  • Cloud Security Engineers — who secure cloud workloads, service identities and cross-environment access paths
  • Security Programme Managers — who need a standards-based roadmap, dependencies and measurable implementation stages

Requirements and prerequisites

Participants should have working experience in enterprise security, networking, cloud platforms or identity and access management. They should understand TCP/IP networking, authentication and authorisation, Active Directory or an equivalent identity provider, firewalls or security groups, and basic cloud workload concepts. Familiarity with Microsoft Entra ID, AWS IAM, Azure, GCP or similar platforms is useful but not mandatory. This is not a penetration-testing or product-administration course, and no programming expertise is required. Participants do not need prior knowledge of NIST SP 800-207, but should be comfortable reading architecture diagrams and discussing security control trade-offs.

Training methodology

The instructor uses NIST SP 800-207 as the working reference throughout, rather than treating Zero Trust as a vendor feature set. Short technical briefings are followed by architecture labs in which participants map access flows, position policy components, write conditional access decisions and assess segmentation options. Teams review a hybrid enterprise case with competing usability, operational and risk requirements. Daily outputs are incorporated into an individual capstone blueprint, and the final day includes a peer architecture review and a 90-day application plan for the participant’s own environment.

Course outline

Day 1: NIST Zero Trust foundations

  • Drivers for replacing perimeter-centric security assumptions
  • NIST SP 800-207 scope, terminology and intended use
  • The seven tenets of Zero Trust Architecture
  • Protect surfaces versus traditional network perimeters
  • Enterprise resources, subjects and access transaction concepts
  • Zero Trust maturity misconceptions and common anti-patterns
  • Business service selection and architecture success criteria

Workshop: Participants select a target business service and produce a first protect-surface statement with security objectives and stakeholders.

Day 2: The NIST logical architecture

  • Policy engine responsibilities and decision inputs
  • Policy administrator responsibilities and enforcement orchestration
  • Policy enforcement point placement patterns
  • Control plane and data plane separation
  • Policy information points and contextual data sources
  • Trust algorithms, risk scoring and decision criteria
  • NIST deployment models for enterprise environments

Workshop: Participants build a logical NIST Zero Trust Architecture diagram showing policy engine, policy administrator, PEPs and information sources.

Day 3: Identity as a policy signal

  • Workforce, privileged, external and machine identity types
  • Authentication assurance and phishing-resistant MFA
  • Authorisation models using RBAC, ABAC and relationship-based access
  • Microsoft Entra ID conditional access policy structure
  • Privileged access workflows and just-in-time elevation
  • Service accounts, workload identities and credential rotation
  • Identity lifecycle events as continuous policy inputs

Workshop: Participants create a conditional access and privileged-access policy matrix for workforce and administrator scenarios.

Day 4: Device, network and workload context

  • Device inventory, ownership and health attestation
  • Endpoint detection and response telemetry as a policy signal
  • Network location as context rather than proof of trust
  • Workload identity and workload-to-workload authentication
  • TLS, mutual TLS and certificate lifecycle considerations
  • API gateways and service mesh enforcement patterns
  • Continuous diagnostics and mitigation feedback loops

Workshop: Participants define required posture and telemetry signals for access to a sensitive internal application.

Day 5: Transaction and data-flow analysis

  • Business service decomposition and dependency mapping
  • User-to-application transaction flow mapping
  • Application-to-application and workload-to-data flows
  • Data classification and sensitivity-driven policy requirements
  • Identifying trust boundaries and enforcement opportunities
  • East-west traffic visibility and inspection points
  • Using packet evidence to validate architecture assumptions

Workshop: Using a case scenario and Wireshark traffic evidence, participants produce a labelled transaction-flow map and enforcement-point shortlist.

Day 6: Segmentation and enforcement design

  • Microsegmentation objectives and enforcement granularity
  • Host-based, network-based and identity-aware segmentation
  • Security groups, firewalls and software-defined policy models
  • Application proxy and zero trust network access patterns
  • PEP failure modes, availability and bypass risk
  • Policy conflict resolution and exception handling
  • Incremental segmentation implementation strategies

Workshop: Participants design a microsegmentation policy for a three-tier application, including allowed flows, enforcement locations and exceptions.

Day 7: Policy design and continuous evaluation

  • Translating access requirements into machine-enforceable policy
  • Policy decision matrices and attribute selection
  • Risk-adaptive access and step-up authentication
  • Session duration, reauthorisation and continuous evaluation
  • Policy testing, simulation and staged rollout methods
  • Logging policy decisions and access-denial events
  • Managing usability, resilience and operational trade-offs

Workshop: Participants write and test a policy decision matrix for normal, elevated-risk and non-compliant-device access requests.

Day 8: Controls, telemetry and operational assurance

  • NIST SP 800-53 Rev. 5 control-family alignment
  • Access control and identification and authentication mappings
  • System and communications protection considerations
  • Audit, accountability and security operations telemetry
  • SIEM use cases for policy and enforcement monitoring
  • Metrics for coverage, policy effectiveness and exception rates
  • Incident response integration and policy refinement

Workshop: Participants map their target-service design to selected NIST SP 800-53 controls and define evidence sources for each control.

Day 9: Implementation roadmap and governance

  • Current-state capability assessment against NIST architecture needs
  • Dependency analysis across IAM, endpoint, network and cloud teams
  • Prioritising protect surfaces by business impact and exposure
  • Sequencing quick wins, foundational capabilities and scale-out phases
  • Architecture governance and policy ownership models
  • Vendor evaluation criteria and interoperability requirements
  • Executive reporting, funding cases and adoption measures

Workshop: Participants create a phased roadmap with capability dependencies, accountable owners, milestones and outcome measures.

Day 10: Architecture capstone and review

  • Capstone blueprint assembly and design-quality checks
  • Validating alignment with NIST SP 800-207 tenets
  • Reviewing policy engine, PEP and telemetry completeness
  • Challenging assumptions through attack and failure scenarios
  • Presenting risk, cost and operational trade-offs to decision-makers
  • Defining 30-, 60- and 90-day implementation actions
  • Establishing architecture review and continuous improvement cadence

Workshop: Participants present their completed Zero Trust Architecture blueprint for peer review and produce a prioritised 90-day application plan.

Tools & standards covered

NIST SP 800-207, NIST SP 800-53 Rev. 5, Microsoft Entra ID, Wireshark

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course introduces the publication’s terminology, tenets, logical components and deployment models before applying them in design work. Prior enterprise security experience is more important than prior familiarity with the document.

Bring a laptop capable of running a modern web browser and viewing diagrams and spreadsheets. Lab materials use guided scenarios involving Microsoft Entra ID policy concepts and Wireshark evidence; participants do not need access to a production tenant or to install tools on corporate systems.

It is designed for security architects, IAM specialists, cloud and network security engineers, and programme leads working on enterprise security change. It is most useful for people who influence architecture, policy or implementation sequencing rather than those seeking an introductory cyber security course.

This course starts with the NIST SP 800-207 reference architecture and evaluates technologies as components of an architecture, not as a prescribed platform. Participants learn how to define policy requirements, enforcement points and evidence needs that can be applied across vendors.

The protect-surface analysis, transaction-flow mapping and policy decision matrix can be used to assess a specific application or high-value service. The phased roadmap also gives participants a structured way to identify dependencies and propose the next implementation decisions.

Each participant leaves with a NIST-aligned Zero Trust Architecture blueprint for a selected case or service. It includes a logical architecture diagram, protect-surface definition, access policy matrix, control mapping, roadmap and 90-day action plan.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Wireshark Network Packet Analysis Training Course

Network incidents, intermittent application failures and suspected data exfiltration are often hidden in packet captures that are too large …

5 Days Certificate

Okta Identity Engine Access Management Security Training Course

Okta administrators and identity security teams are often expected to strengthen access controls without creating sign-in friction, breaking…

5 Days Certificate

Advanced Cyber Threat Hunting and Incident Response Training Course

Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitim…

5 Days Certificate

Advanced Digital Forensics and Malware Analysis Training Course

Security teams need investigators who can move beyond collecting files and alerts to reconstructing an intrusion, establish what executed, i…