Identity for Zero Trust: CISO Readiness Guide
A practical guide for assessing readiness, setting priorities and governing delivery.
How to Use This Guide
This guide is designed for a CISO who needs to decide whether identity can support a Zero Trust strategy, where control gaps create material risk and what to fund next. It is intentionally vendor-independent. Use it to structure an executive workshop, challenge a programme plan or establish a board-ready baseline.
RECOMMENDED SEQUENCE - Read the CISO briefing, score the eight readiness domains, select the weakest high-impact domains, and convert them into a 90/180/365-day plan.
What Readiness Means
Readiness is not the number of identity and access management (IAM) products deployed. It is the organisation’s demonstrated ability to identify every relevant subject, evaluate context, make and enforce a policy decision, observe the result and respond when trust conditions change.
The CISO Briefing
Zero Trust (ZT) removes location as a proxy for trust. That shifts the centre of gravity to identity: who or what is requesting access, under which conditions, to which resource, for what purpose and for how long. If identity data is incomplete, lifecycle controls are slow, authentication is weak or authorization is hidden in applications, the wider ZT architecture inherits those weaknesses.
CISO CONCLUSION - Identity is not one pillar among many. It is the decision context connecting users, machines, devices, workloads, applications and data.
Five Decisions to Make
Define the enterprise identity population, including workforce, partners, customers, workloads, service accounts, APIs, bots and AI agents.
Name accountable owners for identity data, access policy, privileged access and identity threat response.
Set a minimum assurance standard for high-value resources and risky journeys.
Prioritise policy enforcement where consequence and exposure are greatest, not where integration is easiest.
Require evidence of control performance: coverage, latency, exceptions, revocation speed and incident outcomes.





