Deepak Gupta

Control Plane vs Data Plane

Every access request passes through the control plane before reaching the data plane. No exceptions.

Policy Decision Point

The PDP evaluates identity, device posture, context, behavior, and threat intel. Binary: allow or deny.

Policy Enforcement Point

PEPs sit between users and resources. They don't decide, they enforce decisions from the PDP.

Identity Fabric Core

Cloud identity providers like Entra ID, Okta, Google Workspace. MFA is minimum. Continuous auth validates.

Device Trust

A legitimate user on a compromised device is still a threat. Registration, compliance, certificates, risk scores.

Non-Human Identity

Service accounts, API keys, pipelines, AI agents need identity management with equal rigor as humans.

Microsegmentation

Even if attackers compromise one workload, microsegmentation prevents lateral movement. Host or app-layer.

Zero Trust Network Access

ZTNA replaces broad VPN access with identity+device application access. No port probing. No lateral movement.

Visibility & Analytics

SIEM, UEBA, SOAR. Behavioral analytics catches the unknown, compromised accounts with valid credentials.

Common Mistakes

Don't treat identity as solved. Don't ignore east-west. Zero Trust is a strategic multi-year initiative.

Read the Full Blueprint