Summary
SECURE TOMORROW. ii The Journey to Zero Trust is a series of resources on cybersecurity capabilities and architecture topics in support of organizational adoption of modern zero trust principles. Zero trust, with its core concept of never trust and always verify, is the evolution of previous cybersecurity capabilities and models. Aligned with the Office of Management and Budget (OMB) Memorandum (M-) 19-26:1 “Update to the Trusted Internet Connections (TIC) Initiative,” the Cybersecurity and Infrastructure Security Agency (CISA) developed TIC 3.0 guidance to help federal civilian executive branch (FCEB) agencies transition from perimeter-focused architectures (TIC 2.0 or Traditional TIC) to modern security practices. TIC 3.0 provides flexible, non-prescriptive guidance, enabling agencies to secure diverse platforms, services, and environments based on their unique risk tolerance levels. Unlike previous iterations, TIC 3.0 does not mandate routing traffic through TIC access points if agencies use alternative methods to provide situational awareness to both the agency and CISA. The modernized initiative, OMB M-19-26, no longer requires agencies to route traffic through TIC access points if they have a TIC alternative that provides situational awareness to both the agency and CISA through other means.