Begin with the resource, not the product
NIST SP 800-207 describes zero trust as a move away from implicit trust based on network location. For an enterprise, the first useful question is which resources must remain available and protected: applications, data stores, management interfaces, and workflows. Record each resource owner, business impact, data sensitivity, and the users and services that need access. This creates a scope that a security team can actually review.
Map the path of access
For every priority resource, list human and service identities, their devices, authentication methods, current permissions, and the network or cloud path they use. Include employees, contractors, partners and administrators. Compare the permissions granted with the work each identity must perform. Unknown owners, shared accounts, stale privileges and unobserved service connections become concrete remediation tasks rather than vague zero trust objectives.
Turn inventory into a staged plan
NIST SP 1800-35 documents 19 example implementations using different approaches. These are examples, not a universal shopping list. A practical pilot protects one high-value workflow, defines measurable access decisions and logs, tests legitimate user experience, and records exceptions. Expand only after the team can explain why access was allowed or denied and how the resource will be recovered if a control fails. The inventory should be refreshed as assets and business relationships change.
