A company implements a policy where employees are only granted access to the specific systems and data necessary for their role, ensuring no user has more access than needed. The company also requires employees to use their password, and a time-based one-time passcode sent to their mobile device or an authenticator app, to access their internal systems. To safeguard against potential cyber threats, each employee’s laptop, mobile device, and tablet are equipped with security software that continuously monitors signs of suspicious activity, such as malware or unauthorized access attempts.
Which of the following Zero Trust concepts is MISSING from this scenario?