Skip to content
IT Atlas

A layer, not a silo

Security

Security architecture, Zero Trust, detection and response, vulnerability and patch management, monitoring and incident handling across every other layer.

22 articles
A security operations centre: a curved video wall of threat, endpoint and compliance dashboards above three analyst desks with multi monitor setups.
Detection and response turn telemetry into decisions; coverage matters more than tool count.

The five Zero Trust control planes

Every access decision in a modern estate is evaluated across all five planes. A gap in one undermines the others, which is why tool count is a poor measure of coverage.

Plane 1

Identity

Is this really the account holder, right now?

Signals evaluated

  • Authentication method strength
  • Sign in risk
  • Group and role membership
  • Token age

Controls applied

  • Phishing resistant MFA
  • Conditional access
  • Just in time privilege
  • Legacy auth blocked

Common gap, Standing global admin rights and a token replayed after MFA has already succeeded.

Plane 2

Device

Is this device known, healthy and managed?

Signals evaluated

  • Enrolment state
  • Compliance policy result
  • Patch level
  • EDR health

Controls applied

  • Management enrolment
  • Configuration baselines
  • Disk encryption
  • Local admin removal

Common gap, Access granted from an unenrolled personal device because a policy excluded a group.

Plane 3

Network

Should this source be able to reach this destination at all?

Signals evaluated

  • Source location and address
  • Named network
  • East west flow records
  • DNS queries

Controls applied

  • Segmentation
  • Explicit allow rules
  • Private access instead of VPN
  • Egress filtering

Common gap, A flat internal network where one compromised host can reach every server.

Plane 4

Application

Is this the app's intended use by an authorised session?

Signals evaluated

  • Session context
  • Granted OAuth scopes
  • Application risk rating
  • Anomalous API volume

Controls applied

  • App consent governance
  • Least privilege scopes
  • Session controls
  • Reverse proxy inspection

Common gap, A user consented third party app holding broad mailbox and file permissions indefinitely.

Plane 5

Data

Is this data classified, protected and recoverable?

Signals evaluated

  • Classification label
  • Sharing scope
  • Download and export events
  • Backup status

Controls applied

  • Classification and labelling
  • Loss prevention policy
  • Encryption at rest
  • Immutable backups

Common gap, Sensitive records in an unlabelled share with anonymous links and untested restores.

Data Security

Security Architecture

Detection & Response

Incident Response

Exposure Management

Security Operations

Zero Trust