What Zero Trust Architecture Actually Means
NIST SP 800-207 treats ZTA as a set of concepts and principles, not a technical specification to comply with. That distinction matters. The objective is continuous improvement of access control processes and policies in accordance with those principles.
Policies determine access based on attributes of both the subject and the resource. Those attributes include location, type of authentication used, user role, and other variables such as day and time.
Each new request is evaluated on its current conditions.
How This Applies to OT Remote Access
Operational technology (OT) environments present a specific version of this problem. Access to operational systems is typically granted based on implied trust. Threat actors can leverage excess trust to breach networks, often using stolen credentials.
The exact attributes evaluated depend on what the environment supports.
Rockwell Automation describes an Industrial Demilitarized Zone (IDMZ) as a best-practice boundary design for separating business systems from production operations. This boundary helps prevent breaches in IT from accessing OT networks and controllers.
Rockwell Automation describes a five-step process for applying zero trust in OT. The steps are: identify and prioritize business-critical assets as protect surfaces; map transaction flows to and from those surfaces; build a zero trust structure around each in priority order; implement policies for each protect surface; and continuously monitor for anomalous activity.
Rockwell presents these steps in order, though the guide does not specify whether each is a strict prerequisite for the next.
What the NIST Guide Explicitly Excludes
Before applying ZTA concepts to a plant environment, one boundary deserves direct attention. ZTAs for industrial control systems, OT environments, and IoT devices are explicitly out of scope for this project. The guide covers conventional enterprise IT infrastructure: laptops, desktops, servers, and mobile devices.
Prerequisites and Constraints to Verify
The reader decision this article addresses is concrete: which prerequisites and operating constraints must be verified before applying zero trust to an OT remote-access path?
Many critical infrastructure organizations operate on legacy systems without modern cybersecurity controls in place, such as network segmentation, multi-factor authentication, frequent asset inventories, or effective OT patching.
Verify whether individual identities exist for every remote accessor, including third-party vendors and contractors.
Rockwell Automation states that a connected enterprise requires a comprehensive approach to network segmentation, including IDMZ, and an expert partner who understands how to apply strategies such as Zero Trust in industrial environments.
Timing and access continuity. In an OT environment, a blocked or delayed remote-access session during an equipment failure may extend downtime. Does the access path design include a fallback procedure for time-critical maintenance scenarios?
Enterprises should use a risk-based approach to set and prioritize milestones for gradual adoption and integration of ZTA.
The Distinction That Matters
There is no single approach for migrating to ZTA that is best for all enterprises.
Those are engineering questions that require evidence from the specific environment, not assumptions carried over from an enterprise IT deployment.

