# Zero Trust Framework — Implementation Workbook

Version: 1.0
Published: 2026-07-27
Last updated: 2026-07-27
Owner: Rusaka Research
Review frequency: Every 6 months

## Decision statement

What decision must this workbook support?

________________________________________________________________________________

## Scope and exclusions

In scope:

________________________________________________________________________________

Out of scope:

________________________________________________________________________________

## Baseline evidence register

| Evidence item | Source | Date | Owner | Verified by | Status |
|---|---|---|---|---|---|
| | | | | | |
| | | | | | |
| | | | | | |

## Assumption register

| Assumption | Rationale | Decision affected | Downside case | Test | Owner | Review date |
|---|---|---|---|---|---|---|
| | | | | | | |
| | | | | | | |

## Options and decision criteria

| Option | Outcome | Feasibility | Cost | Time | Risk | Reversibility | Recommendation |
|---|---:|---:|---:|---:|---:|---:|---|
| | | | | | | | |
| | | | | | | | |

## Implementation plan

| Phase | Entry evidence | Actions | Owner | Control | Exit evidence | Due date |
|---|---|---|---|---|---|---|
| 1. Design — Zero Trust Framework | | During design, use Zero Trust Framework to make comparable decisions with a consistent structure. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed framework, rationale, and exception register. | |
| 2. Pilot — Zero Trust Framework | | During pilot, use Zero Trust Framework to make comparable decisions with a consistent structure. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed framework, rationale, and exception register. | |
| 3. Scale — Zero Trust Framework | | During scale, use Zero Trust Framework to make comparable decisions with a consistent structure. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed framework, rationale, and exception register. | |
| 4. Operations — Zero Trust Framework | | During operations, use Zero Trust Framework to make comparable decisions with a consistent structure. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed framework, rationale, and exception register. | |
| 5. Discovery — Zero Trust Framework | | During discovery, use Zero Trust Framework to make comparable decisions with a consistent structure. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a completed framework, rationale, and exception register. | |

## Measures and thresholds

| Measure | Definition | Source | Baseline | Target | Threshold | Owner | Frequency |
|---|---|---|---:|---:|---:|---|---|
| | | | | | | | |
| | | | | | | | |

## Risk and control register

| Risk | Cause | Impact | Preventive control | Detective control | Owner | Residual risk |
|---|---|---|---|---|---|---|
| | | | | | | |
| | | | | | | |

## Review checklist

- [ ] 1. Data governance: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 2. Capability and resourcing: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 3. Scale readiness: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 4. Review and renewal: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 5. Decision boundary: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 6. Stakeholder map: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 7. Current-state baseline: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 8. Evidence design: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 9. Operating model: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 10. Architecture and integration: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 11. Risk and compliance: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 12. Economics and value: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 13. Delivery sequencing: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 14. Vendor and partner assessment: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.

## Approval record

| Role | Name | Decision | Conditions | Date |
|---|---|---|---|---|
| Accountable owner | | | | |
| Subject-matter reviewer | | | | |
| Risk or control reviewer | | | | |

## Authoritative references

- https://www.nist.gov/cyberframework — Authoritative reference 1 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.
- https://owasp.org/www-project-top-ten/ — Authoritative reference 2 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.
- https://www.cisa.gov/resources-tools — Authoritative reference 3 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.

## Related Rusaka resources

- https://www.rusaka.com/resources/frameworks
- https://www.rusaka.com/resources/guides/cybersecurity-strategy-guide
- https://www.rusaka.com/resources/checklists/cloud-security-checklist
- https://www.rusaka.com/resources/frameworks/corporate-governance-framework
- https://www.rusaka.com/resources/frameworks/tokenomics-framework
- https://www.rusaka.com/resources/glossary/security-controls-library

## Important limitation

This educational workbook does not replace legal, investment, tax, accounting,
security, clinical, regulatory, or other qualified professional advice. Confirm
current requirements and obtain formal organisational approval where applicable.
