Federal Zero Trust

OMB M-22-09

OMB Memorandum M-22-09, "Moving the U.S. Government Toward Zero Trust Cybersecurity Principles", issued January 26, 2022. The memorandum sets specific federal zero trust goals across five pillars (identity, devices, networks, applications, and data) and required federal civilian executive branch agencies to meet them by the end of fiscal year 2024. Headline requirements include enterprise-managed identities with phishing-resistant multi-factor authentication, encrypted DNS and HTTP traffic, isolation of agency applications from networks, and treatment of every application as internet-facing for security purposes.

The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.