Trust & Compliance / CISA Zero Trust

CISA Zero Trust

Advance the data pillar, not just the network.

CISA’s Zero Trust Maturity Model is the roadmap federal agencies — and many state, local and critical infrastructure organizations — use to measure zero trust progress. The Data pillar is often the least mature. XQ closes that gap by encrypting every data object, binding access policy to it, and logging every decision, so data pillar functions can move from Traditional toward Advanced and Optimal.

Built for Federal civilian agencies executing zero trust strategies · State, local and critical infrastructure security teams · Integrators supporting federal zero trust programs

At a glance

FrameworkCISA Zero Trust Maturity Model v2.0 (April 2023)

PillarsIdentity, Devices, Networks, Applications & Workloads, Data

StagesTraditional, Initial, Advanced, Optimal

XQ coversData pillar, plus visibility, automation and governance

Works with Microsoft 365 · Microsoft Purview · AWS GovCloud · Azure Government · On-premises · SIEM tools

Know your data

Discover and label sensitive data so protection matches its category.

Grant just enough access

Access is decided per request from identity, policy and data category — and can be revoked at any time.

Encrypt everywhere

Data stays encrypted at rest and in transit, with keys managed apart from the data.

What the Zero Trust Maturity Model measures

Version 2.0 of the model scores five pillars — Identity, Devices, Networks, Applications and Workloads, and Data — plus three cross-cutting capabilities: Visibility and Analytics, Automation and Orchestration, and Governance. Each function is rated at one of four stages: Traditional, Initial, Advanced or Optimal.

The Data pillar has five functions: data inventory management, data categorization, data availability, data access and data encryption. At the Advanced stage, access decisions consider identity, device risk and data category, and encryption is applied broadly to data at rest and in transit. At Optimal, inventory and labeling are continuous and automated, and access decisions are dynamic.

How XQ maps to the Data pillar

Data pillar functionHow XQ helps
Data inventory managementThe Governance Scanner discovers sensitive data across your repositories, so inventory covers the data that matters rather than only known systems.
Data categorizationData and metadata tagging classifies information as it is created, and labels sync with Microsoft Purview so policy follows the data’s category.
Data availabilityProtected data stays in your existing storage and backups, and authorized users can open it wherever it is stored or shared.
Data accessEvery decryption is an access decision based on identity, policy and data category — time-limited where needed and revocable in real time.
Data encryptionEach data object is encrypted with its own key at rest and in transit, and keys are managed separately from the data they protect.

Scoring your agency’s data pillar?

Validated in the AWS ZTAG-I reference architecture

AWS built AWS ZTAG-I — the Zero Trust Accelerator for Government – Integrated — as a tested, integrated zero trust stack aligned with the CISA Zero Trust Maturity Model and the DoD Zero Trust Strategy. AWS validated XQ for its Data pillar: AWS encrypts stored data, while XQ adds encryption for sensitive information and communications, monitors data access, enforces encryption policy and assesses access risk.

The cross-cutting capabilities

  • Visibility and analytics: every encryption, decryption and access attempt is logged and can be streamed to your SIEM.
  • Automation and orchestration: policy is enforced automatically on every access, and APIs let you apply protection inside existing workflows.
  • Governance: keys and policies are managed centrally, with reports on encryption coverage and access for auditors.

Resilience against ransomware and exfiltration

Because data is encrypted and only authorized parties can obtain keys, an attacker who gets past the perimeter or steals files still cannot read them. Access to exposed data can be revoked after the fact.

Related resources and articles

CISA Zero Trust, answered directly.

What is the CISA Zero Trust Maturity Model?

It is CISA’s framework for measuring zero trust progress across five pillars — Identity, Devices, Networks, Applications and Workloads, and Data — and three cross-cutting capabilities, each rated Traditional, Initial, Advanced or Optimal. Version 2.0 was published in April 2023.

Which data pillar functions does XQ address?

All five: data inventory management, data categorization, data availability, data access and data encryption, along with the visibility, automation and governance capabilities that support them.

Has XQ been validated in a federal zero trust reference architecture?

Yes. AWS validated XQ for the Data pillar of AWS ZTAG-I, the Zero Trust Accelerator for Government – Integrated, which is aligned with the CISA Zero Trust Maturity Model and the DoD Zero Trust Strategy. AWS encrypts stored data, while XQ adds encryption for sensitive information and communications, monitors data access, enforces encryption policy and assesses access risk.

Can XQ help an agency reach the Advanced stage for data?

XQ is designed to deliver the controls CISA describes at the Advanced stage — attribute-based access decisions, broad encryption at rest and in transit, and protected keys — with automation that supports the path to Optimal. Your assessor determines the final rating.

Does XQ replace identity or network tools?

No. XQ works with your identity provider and network controls, and adds protection to the data itself so it stays governed wherever it goes.

Mature your data pillar.

Request a briefing on moving data inventory, access and encryption toward Advanced and Optimal.