Zero Trust Architecture Using NIST SP 800-207 Training Course
| Course code | SD-CS-060 |
|---|---|
| Duration | 10 days |
| Level | Intermediate to Advanced |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Perimeter-based security controls do not adequately protect organisations where users work remotely, workloads span cloud and data centre environments, and applications depend on APIs, SaaS platforms and third parties. Security architects and engineering teams need a defensible way to replace implicit network trust with explicit, continuously evaluated access decisions. This course provides a practical route from the principles in NIST SP 800-207 to an architecture that can be prioritised, implemented and measured across a real enterprise environment.
Participants examine the NIST Zero Trust Architecture model in detail: the policy engine, policy administrator, policy enforcement points, data plane and control plane; identity, device, application and workload signals; and the seven tenets of zero trust. They learn to define protect surfaces, map transaction flows, select policy decision inputs, design least-privilege access policies and integrate identity, endpoint, network and telemetry controls. The course also addresses hybrid cloud patterns, microsegmentation, privileged access, encryption, continuous diagnostics and NIST SP 800-53 control alignment.
Instruction combines expert-led architecture sessions with structured design workshops, scenario analysis and hands-on policy exercises using Microsoft Entra ID and network inspection tools. Each participant develops a NIST SP 800-207-aligned Zero Trust Architecture blueprint for a selected business service or organisational case. The final deliverable includes a protect-surface definition, logical architecture, policy decision matrix, phased implementation roadmap, control mapping and measures for evaluating progress.
The course is suited to experienced cyber security professionals who must turn Zero Trust strategy into engineering decisions, implementation requirements and investment cases. Managers gain staff who can distinguish a standards-based architectural programme from a product-led security refresh.
Course objectives
By the end of this course, participants will be able to:
- Interpret NIST SP 800-207 components, tenets and deployment models for a hybrid enterprise environment
- Define protect surfaces and map data, application, workload and user transaction flows
- Design policy decision points and policy enforcement points using the NIST Zero Trust Architecture logical model
- Construct a policy decision matrix using identity, device posture, workload, network and risk signals
- Apply least-privilege access patterns to workforce, privileged, application and machine identities
- Map Zero Trust architectural decisions to relevant NIST SP 800-53 Rev. 5 control families
- Evaluate microsegmentation, continuous diagnostics and telemetry requirements for a target service
- Produce a phased Zero Trust Architecture blueprint and implementation roadmap for a business use case
Benefits of attending
For you
- Build the ability to lead NIST SP 800-207-based architecture discussions with security, infrastructure and business stakeholders
- Gain a reusable method for converting Zero Trust principles into policy, enforcement and telemetry requirements
- Strengthen credibility when assessing vendor Zero Trust claims against a recognised NIST reference architecture
- Create portfolio-ready architecture artefacts including a policy matrix, logical design and implementation roadmap
- Prepare for senior security architecture responsibilities involving hybrid cloud access and identity-led security controls
For your organisation
- Establish a common NIST-based language for Zero Trust decisions across security, network, cloud and IAM teams
- Reduce reliance on implicit network trust by identifying enforceable controls around high-value services and data
- Improve investment decisions by separating architectural capabilities from individual vendor product claims
- Produce phased implementation plans that expose dependencies in identity, endpoint posture, telemetry and segmentation
- Create traceable links between Zero Trust design choices and NIST SP 800-53 control objectives
Target competencies
Who should attend
- Security Architects — who must translate Zero Trust principles into enterprise security architecture and target-state designs
- Cyber Security Architects — who need to specify policy enforcement, telemetry and control integrations across hybrid environments
- Identity and Access Management Leads — who design conditional access, privileged access and identity assurance policies
- Network Security Engineers — who implement segmentation and enforcement controls without relying on broad network trust
- Cloud Security Engineers — who secure cloud workloads, service identities and cross-environment access paths
- Security Programme Managers — who need a standards-based roadmap, dependencies and measurable implementation stages
Requirements and prerequisites
Participants should have working experience in enterprise security, networking, cloud platforms or identity and access management. They should understand TCP/IP networking, authentication and authorisation, Active Directory or an equivalent identity provider, firewalls or security groups, and basic cloud workload concepts. Familiarity with Microsoft Entra ID, AWS IAM, Azure, GCP or similar platforms is useful but not mandatory. This is not a penetration-testing or product-administration course, and no programming expertise is required. Participants do not need prior knowledge of NIST SP 800-207, but should be comfortable reading architecture diagrams and discussing security control trade-offs.
Training methodology
The instructor uses NIST SP 800-207 as the working reference throughout, rather than treating Zero Trust as a vendor feature set. Short technical briefings are followed by architecture labs in which participants map access flows, position policy components, write conditional access decisions and assess segmentation options. Teams review a hybrid enterprise case with competing usability, operational and risk requirements. Daily outputs are incorporated into an individual capstone blueprint, and the final day includes a peer architecture review and a 90-day application plan for the participant’s own environment.
Course outline
Day 1: NIST Zero Trust foundations
- Drivers for replacing perimeter-centric security assumptions
- NIST SP 800-207 scope, terminology and intended use
- The seven tenets of Zero Trust Architecture
- Protect surfaces versus traditional network perimeters
- Enterprise resources, subjects and access transaction concepts
- Zero Trust maturity misconceptions and common anti-patterns
- Business service selection and architecture success criteria
Workshop: Participants select a target business service and produce a first protect-surface statement with security objectives and stakeholders.
Day 2: The NIST logical architecture
- Policy engine responsibilities and decision inputs
- Policy administrator responsibilities and enforcement orchestration
- Policy enforcement point placement patterns
- Control plane and data plane separation
- Policy information points and contextual data sources
- Trust algorithms, risk scoring and decision criteria
- NIST deployment models for enterprise environments
Workshop: Participants build a logical NIST Zero Trust Architecture diagram showing policy engine, policy administrator, PEPs and information sources.
Day 3: Identity as a policy signal
- Workforce, privileged, external and machine identity types
- Authentication assurance and phishing-resistant MFA
- Authorisation models using RBAC, ABAC and relationship-based access
- Microsoft Entra ID conditional access policy structure
- Privileged access workflows and just-in-time elevation
- Service accounts, workload identities and credential rotation
- Identity lifecycle events as continuous policy inputs
Workshop: Participants create a conditional access and privileged-access policy matrix for workforce and administrator scenarios.
Day 4: Device, network and workload context
- Device inventory, ownership and health attestation
- Endpoint detection and response telemetry as a policy signal
- Network location as context rather than proof of trust
- Workload identity and workload-to-workload authentication
- TLS, mutual TLS and certificate lifecycle considerations
- API gateways and service mesh enforcement patterns
- Continuous diagnostics and mitigation feedback loops
Workshop: Participants define required posture and telemetry signals for access to a sensitive internal application.
Day 5: Transaction and data-flow analysis
- Business service decomposition and dependency mapping
- User-to-application transaction flow mapping
- Application-to-application and workload-to-data flows
- Data classification and sensitivity-driven policy requirements
- Identifying trust boundaries and enforcement opportunities
- East-west traffic visibility and inspection points
- Using packet evidence to validate architecture assumptions
Workshop: Using a case scenario and Wireshark traffic evidence, participants produce a labelled transaction-flow map and enforcement-point shortlist.
Day 6: Segmentation and enforcement design
- Microsegmentation objectives and enforcement granularity
- Host-based, network-based and identity-aware segmentation
- Security groups, firewalls and software-defined policy models
- Application proxy and zero trust network access patterns
- PEP failure modes, availability and bypass risk
- Policy conflict resolution and exception handling
- Incremental segmentation implementation strategies
Workshop: Participants design a microsegmentation policy for a three-tier application, including allowed flows, enforcement locations and exceptions.
Day 7: Policy design and continuous evaluation
- Translating access requirements into machine-enforceable policy
- Policy decision matrices and attribute selection
- Risk-adaptive access and step-up authentication
- Session duration, reauthorisation and continuous evaluation
- Policy testing, simulation and staged rollout methods
- Logging policy decisions and access-denial events
- Managing usability, resilience and operational trade-offs
Workshop: Participants write and test a policy decision matrix for normal, elevated-risk and non-compliant-device access requests.
Day 8: Controls, telemetry and operational assurance
- NIST SP 800-53 Rev. 5 control-family alignment
- Access control and identification and authentication mappings
- System and communications protection considerations
- Audit, accountability and security operations telemetry
- SIEM use cases for policy and enforcement monitoring
- Metrics for coverage, policy effectiveness and exception rates
- Incident response integration and policy refinement
Workshop: Participants map their target-service design to selected NIST SP 800-53 controls and define evidence sources for each control.
Day 9: Implementation roadmap and governance
- Current-state capability assessment against NIST architecture needs
- Dependency analysis across IAM, endpoint, network and cloud teams
- Prioritising protect surfaces by business impact and exposure
- Sequencing quick wins, foundational capabilities and scale-out phases
- Architecture governance and policy ownership models
- Vendor evaluation criteria and interoperability requirements
- Executive reporting, funding cases and adoption measures
Workshop: Participants create a phased roadmap with capability dependencies, accountable owners, milestones and outcome measures.
Day 10: Architecture capstone and review
- Capstone blueprint assembly and design-quality checks
- Validating alignment with NIST SP 800-207 tenets
- Reviewing policy engine, PEP and telemetry completeness
- Challenging assumptions through attack and failure scenarios
- Presenting risk, cost and operational trade-offs to decision-makers
- Defining 30-, 60- and 90-day implementation actions
- Establishing architecture review and continuous improvement cadence
Workshop: Participants present their completed Zero Trust Architecture blueprint for peer review and produce a prioritised 90-day application plan.
Tools & standards covered
NIST SP 800-207, NIST SP 800-53 Rev. 5, Microsoft Entra ID, Wireshark
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Wireshark Network Packet Analysis Training Course
Network incidents, intermittent application failures and suspected data exfiltration are often hidden in packet captures that are too large …
Okta Identity Engine Access Management Security Training Course
Okta administrators and identity security teams are often expected to strengthen access controls without creating sign-in friction, breaking…
Advanced Cyber Threat Hunting and Incident Response Training Course
Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitim…
Advanced Digital Forensics and Malware Analysis Training Course
Security teams need investigators who can move beyond collecting files and alerts to reconstructing an intrusion, establish what executed, i…