The rule that the internal network is not safe by itself. Every request is checked as if it came from outside.
Old-style security was a castle with a moat. You guard the wall. Whoever gets through the gate walks around the yard freely. Except the wall is gone. People work from home, from the train, from the cafe. Software lives in the cloud. And the castle always had an old flaw. NIST says it plainly: once attackers breach the perimeter, nothing stops them moving further in.
Zero Trust flips the logic. A network is not safe just because it is yours. NIST even assumes the attacker is already inside, and wants the company network treated like any outside one. Every request goes through a check. Access is granted per session, and it is the least access that gets the job done.
An example. The accountant opens the payroll software from a laptop in the office. Under the old model, being in the office was enough. Under the new one the software asks separately: is this really him, is this his laptop, does he need this exact report right now. If someone has stolen his password and logs in from an unknown device, the right password alone is not enough.
The idea did not appear overnight. As early as 2004 the Jericho Forum was talking about taking down the wall around the network. In 2010 Kindervag gave it its name. In 2014 Google described its own version, BeyondCorp: internal applications move onto the internet, and the company stops relying on a protected internal network.
What it is not
Zero Trust is not a box you buy. NIST says explicitly that it is a set of guiding principles, not a single architecture. And that getting there is a journey that does not happen by swapping all the technology at once. Most organisations live for a long time half in the old model and half in the new. If someone sells you "Zero Trust in a box", they are selling you a label.
On a small scale it looks like this. Every internal tool has its own login and asks who you are, even when you are in the office. It asks again. Every time.