zero-trust-architect

Design Zero Trust Architecture and SASE deployment models with NIST SP 800-207 mapping.

7|Updated Mar 5, 2026
One-click install
npx skills add https://github.com/rloisell/rl-agents-n-skills --skill zero-trust-architect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: zero-trust-architect
Source: https://github.com/rloisell/rl-agents-n-skills/tree/main/zero-trust-architect
Command: npx skills add https://github.com/rloisell/rl-agents-n-skills --skill zero-trust-architect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps architects eliminate implicit trust in networks by designing and documenting Zero Trust Architecture and SASE deployment models that provide identity-first access, microsegmentation, and policy-engine-driven enforcement across cloud, branch, and remote users.

Core Features & Use Cases

  • Architecture design: templates and component maps for ZTNA, SWG, CASB, FWaaS, SD-WAN and PoP considerations.
  • Policy engine & PDP/PEP design: guidance on identity checks, device posture, risk scoring, enforcement points, and least-privilege access patterns.
  • Vendor evaluation & migration planning: scorecards, deployment models (single-vendor, dual-vendor, hybrid), and mappings to NIST SP 800-207 and CISA maturity pillars.
  • Use Case: create a phased SASE migration plan for an enterprise moving from MPLS/VPN to cloud-native ZTNA with integrated SD-WAN and DLP.

Quick Start

Ask the skill to design a Zero Trust Architecture and SASE deployment plan for your enterprise including recommended components, a vendor scorecard, and a migration roadmap.

Frequently Asked Questions about zero-trust-architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design a Zero Trust Architecture that maps to NIST SP 800-207?

To design a Zero Trust Architecture mapped to NIST SP 800-207, define identity-first access controls, establish Policy Decision Points (PDP), Policy Enforcement Points (PEP), and integrate device posture checks for least-privilege enforcement across cloud, branch, and remote user scenarios.

What's the best way to plan a SASE migration from MPLS and VPN to cloud-native ZTNA?

Planning a SASE migration from MPLS/VPN to cloud-native ZTNA requires a phased roadmap that integrates SD-WAN, Secure Web Gateways (SWG), Cloud Access Security Brokers (CASB), and Firewall-as-a-Service (FWaaS) to eliminate implicit network trust and enable secure remote access.

How do I evaluate SASE and ZTNA vendors for enterprise network security?

Evaluating SASE and ZTNA vendors involves using a scorecard to compare single-vendor, dual-vendor, and hybrid deployment models against CISA maturity pillars and NIST SP 800-207 requirements to determine the best fit for your enterprise architecture.

How does a policy engine handle device posture and risk scoring in a Zero Trust model?

A Zero Trust policy engine handles device posture and risk scoring by continuously evaluating user identity and device health at the Policy Decision Point, dynamically adjusting access permissions and enforcing least-privilege rules at the Policy Enforcement Point.

Can I use microsegmentation for remote users accessing cloud applications?

Yes, microsegmentation can secure remote users accessing cloud applications by applying identity-first policy enforcement and Software-Defined Wide Area Network (SD-WAN) integration to isolate resources and eliminate lateral movement threats within the SASE framework.