The Zero Trust approach is based in particular on the idea that access should not be considered secure simply because it comes from the internal network.
Visibility therefore becomes fundamental.
A SIEM can contribute to this visibility by correlating:
- identify
- device
- location
- application
- network
- privileges
- behavior.
SIEM is not a Zero Trust solution on its own, but it can contribute to the monitoring of the Zero Trust environment.