ZERO TRUST ARCHITECTURE AND PROSPECTS FOR ITS IMPLEMENTATION IN THE GOVERNMENT SECTOR OF UKRAINE

Authors

  • I.I. Bobok Odessa Polytechnic National University Author
  • A.A. Kobozieva Odessa National Maritime University Author

DOI:

https://doi.org/10.17721/2519-481X/2025/88-06

Keywords:

zero trust, government information systems, cybersecurity, hybrid warfare, identity, microsegmentation, adaptive authentication

Abstract

The escalation of cyberattacks as a key component of hybrid warfare poses significant challenges to the security of state information systems. In the context of ongoing military aggression against Ukraine and large-scale attacks targeting critical infrastructure, the traditional perimeter-based security model has proven insufficient under conditions of blurred network boundaries and widespread adoption of cloud technologies and remote access. A promising alternative is the Zero Trust Architecture (ZTA), built on the principles of "never trust, always verify," least privilege access, and continuous monitoring. The aim of this study is to substantiate an adapted ZTA implementation model for Ukrainian government networks, considering national regulatory requirements, limited financial and human resources, and heightened risks during hybrid aggression. The paper provides an overview of leading international frameworks, including NIST SP 800-207, CISA Zero Trust Maturity Model, and NCSC Design Principles, and identifies key barriers to their application in Ukraine. These barriers include outdated infrastructure, regulatory inconsistencies, insufficient personnel expertise, and restricted budgets. The proposed conceptual model incorporates a phased implementation strategy across five layers: identity and access management, dynamic access control, network microsegmentation, data protection, and continuous monitoring with behavioral analytics. The model also integrates federated identity management, multi-factor authentication, contextual risk-based access control, and centralized monitoring via SIEM and SOAR platforms. The expected result is an increased level of cyber resilience in government networks without a significant reduction in usability, ensuring compliance with national cybersecurity standards and readiness for hybrid threats.

Author Biographies

References

1. Zhou, Z., Duan, D., and Xu H. (2024). “Zero-Trust Zero-Communication Defence against Hybrid Cyberattacks in Distributed Energy Resources Using Mean Field Reinforcement Leaning”, Energies, 17(20), 5057. Available at: https://doi.org/10.3390/en17205057

2. Nisha T N, DhanyaPramod, and Ravi Singh. (2023). “Zero trust security model: Defining new boundaries to organizational network”, Proceedings of the 2023 Fifteenth International Conference on Contemporary Computing (IC3-2023). New York, NY, USA, pp. 603–609.

3. Executive Order No. 14028, 3 C.F.R. 14028 (2021). Available at: https://public-inspection.federalregister.gov/2021-10460.pdf (Accessed: 20.06.2025).

4. The Department of Homeland Security. Zero Trust Implementation Strategy. Available at: https://www.dhs.gov/sites/default/files/2024-02/24_0129_cio_zero_trust_implementation_strategy_october.pdf (Accessed: 20.06.2025).

5. Phiayura, P., and Teerakanok, S. (2023). “A Comprehensive Framework for Migrating to Zero Trust Architecture”, IEEE Access, 11, pp.19487–19511. Available at: https://doi.org/10.1109/ACCESS.2023.3248622.

6. National Institute of Standards and Technology (NIST). (2020). Zero Trust Architecture (NIST Special Publication 800-207).

7. Cybersecurity and Infrastructure Security Agency. Zero Trust Maturity Model, Version 2.0. Available at: https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf (Accessed: 20.06.2025).

8. The National Cyber Security Centre. Zero trust architecture design principles. Available at: https://www.ncsc.gov.uk/collection/zero-trust-architecture (Accessed: 20.06.2025).

9. Australian Cyber Security Centre. Essential Eight. Available at: https://www.cyber.gov.au/resources-business-and-government/essential-cybersecurity/essential-eight (Accessed: 20.06.2025).

10. The Law of Ukraine “On information protection in information and communication systems”. 1994. Vidomosti Verchvnoy Rady Ukrainy. 31. p. 286.

11. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance) (2016) Official Journal L 119, 1-88. http://data.europa.eu/eli/reg/2016/679/oj

12. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)

13. The Law of Ukraine “On Access to Public Information”. 2011. Vidomosti Verchvnoy Rady Ukrainy. 32. p. 314.

14. Khudoliy, A. (2019). “Kiberbezbeka: suchasni vyklyky pered Ukrainoyu” [Cybersecurity: modern challenges of Ukraine] Acta De Historia & Politica: Saeculum XXI, 1, pp. 138–146. Available at: https://doi.org/10.26693/ahpsxxi2019.01.138

15. Evsyukova, O. (2021). “Osoblyvosti pidgotovky fakhivtsiv u sferi kiberbezpeky: suchasni vyklyky s perspektyvy” [Features of training of specialists in the field of cyber security: current challenges and prospects]. Derzhavne Upravlinnya: Udoskonalennya ta Rozvytok. 2. Available at: https://doi.org/10.32702/2307-2156-2021.2.2

Published

2025-11-21

Issue

Section

INFORMATION TECHNOLOGIES