Regulated SaaS providers must defend exposed web applications and APIs, distributed cloud control paths, BYOD-heavy workforces, and privileged internal workflows while simultaneously preserving availability, auditability, and user experience. Zero Trust Architecture (ZTA) is widely adopted as a target model for these environments; yet practical implementations frequently devolve into either an unworkable internal deny-all posture that fractures operations, or an insufficiently rigorous configuration that leaves unjustified standing trust intact. This paper proposes the Minimum Standing Trust (MST) framework: an operations optimization model for security operations centers (SOCs) that support SaaS platforms processing regulated data, including PHI, PII, PCI-DSS-scoped data, and GDPR-governed information. MST formalizes a two-plane enforcement architecture. At the application edge, the prescribed posture is strict minimization of allowed ingress, enforced through WAF controls, NIDS visibility, bidirectional abuse-list auto-blocking (inbound and outbound, at both network and endpoint layers), and tightly governed exception handling. Inside the distributed enterprise, ZTA is implemented not as universal blocking but as the progressive removal of standing trust through strong identity, device posture, session-aware authorization, just-in-time privilege elevation, and behavioral context. The paper further argues that the operational hinge of this model is a unified telemetry plane spanning SIEM, EDR, XDR, WAF, NIDS, IAM, VPN or ZTNA, cloud, and data-access events. On this foundation, agentic AI can safely accelerate triage and response—but only when autonomy is bounded by policy, reversibility, and blast-radius constraints derived from organizational risk tolerance. The resulting framework reduces analyst burden, limits unnecessary access, improves audit-evidence generation, and offers a concrete path for aligning Zero Trust theory with cyber defense practice in regulated SaaS environments.
Rose, S., Borchert, O., Mitchell, S. and Connelly, S. (2020) Zero Trust Architecture. NIST Special Publication 800-207. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207-draft2
Kindervag, J. (2010) Build Security into Your Network’s DNA: The Zero Trust Network Architecture. Technical Report, Forrester Research.
Ward, R. and Beyer, B. (2014) BeyondCorp: A New Approach to Enterprise Security. USENIX , 39, 6-11.
Osborn, B., McAdams, J., Beyer, B. and Ward, R. (2016) BeyondCorp: DESIGN to Deployment at Google. USENIX , 41, 28-34.
Gilman, E. and Barth, D. (2017) Zero Trust Networks: Building Secure Systems in Untrusted Networks. O’Reilly Media.
Chandramouli, R. (2023) A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments. NIST Special Publication 800-207A, National Institute of Standards and Technology.
Cybersecurity and Infrastructure Security Agency (2023) Zero Trust Maturity Model, Version 2.0. Technical Report, CISA.
United States Department of Defense (2022) Department of Defense Zero Trust Strategy. Technical Report, Office of the Chief Information Officer, U.S. Department of Defense.
Executive Office of the President (2021) Executive Order 14028: Improving the Nation’s Cybersecurity. Federal Register , 86, 26633-26641.
Buck, C., Olenberger, C., Schweizer, A., Völter, F. and Eymann, T. (2021) Never Trust, Always Verify: A Multivocal Literature Review on Current Knowledge and Research Gaps of Zero-Trust. Computers & Security , 110, Article ID: 102436. https://doi.org/10.1016/j.cose.2021.102436
CrowdStrike (2025) CrowdStrike Global Threat Report. Technical Report, CrowdStrike. https://www.crowdstrike.com/global-threat-report/
Cisco Talos Intelligence Group (2025) Cisco Talos Year in Review 2024. Technical Report, Cisco Systems. https://blog.talosintelligence.com/
Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C., Pennington, A.G. and Thomas, C.B. (2018) MITRE ATT&CK: Design and Philosophy. Technical Report MP180360R1, The MITRE Corporation.
Virtual Security Operations Center
Saltzer, J.H. and Schroeder, M.D. (1975) The Protection of Information in Computer Systems. Proceedings of the IEEE , 63, 1278-1308. https://doi.org/10.1109/proc.1975.9939
Tabassi, E. (2023) Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, National Institute of Standards and Technology.
Autio, C., Schwartz, R., Stanley, K., Tabassi, E. and Hodge, J. (2024) Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST AI 600-1, National Institute of Standards and Technology.
National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Australian Cyber Security Centre, New Zealand National Cyber Security Centre and United Kingdom National Cyber Security Centre (2024) Deploying AI Systems Securely: Best Practices for Deploying Secure and Resilient AI Systems. Technical Report, Joint Cybersecurity Information.
National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Australian Signals Directorate’s Australian Cyber Security Centre and International Partners (2025) AI Data Security: Best Practices for Securing Data Used to Train and Operate AI Systems. Technical Report, Joint Cybersecurity Information.
National Cyber Security Centre (2023) Guidelines for Secure AI System Development. Technical Report, NCSC.
Cunningham, C. (2018) The Forrester Wave: Zero Trust eXtended (ZTX) Ecosystem Platform Providers, Q3 2018. Technical Report, Forrester Research.
Beyer, B., Cittadini, L., Saltonstall, M. and Spear, B. (2017) Migrating to BeyondCorp: Maintaining Productivity While Improving Security. USENIX , 42, 49-55.
Syed, N.F., Shah, S.W., Shaghaghi, A., Anwar, A., Baig, Z. and Doss, R. (2022) Zero Trust Architecture (ZTA): A Comprehensive Survey. IEEE Access , 10, 57143-57179. https://doi.org/10.1109/access.2022.3174679
de Chaves, S.A., Westphall, C.B. and Lamin, F.R. (2010) SLA Perspective in Security Management for Cloud Computing. 2010 Sixth International Conference on Networking and Services , Cancun, 7-13 March 2010, 212-217. https://doi.org/10.1109/icns.2010.36
Balasubramanian, V., Murugavel, P., Marikkannan, M. and Latha, B. (2021) BYOD Security Challenges and Solutions in Enterprise Environments: A Systematic Review. International Journal of Information Security , 20, 557-573.
Sandhu, R.S. and Samarati, P. (1994) Access Control: Principle and Practice. IEEE Communications Magazine , 32, 40-48. https://doi.org/10.1109/35.312842
Hu, V.C., Ferraiolo, D., Kuhn, R., Schnitzer, A., Sandlin, K., Miller, R. and Scarfone, K. (2014) Guide to Attribute Based Access Control (ABAC) Definition and Considerations. NIST Special Publication 800-162, National Institute of Standards and Technology.
Tuor, A., Kaplan, S., Hutchinson, B., Nichols, N. and Robinson, S. (2017) Deep Learning for Unsupervised Insider Threat Detection in Structured Cybersecurity Data Streams. Proceedings of the AAAI -17 Workshop on AI for Cyber Security , San Francisco, 4-5 February 2017, 224-231.
Liu, A.X. and Gouda, M.G. (2008) Diverse Firewall Design. IEEE Transactions on Parallel and Distributed Systems , 19, 1100-1112.
Shandilya, V., Simmons, C.B. and Shiva, S. (2014) Use of Attack Graphs in Security Systems. Journal of Computer Networks and Communications , 2014, Article ID: 818957. https://doi.org/10.1155/2014/818957
Garey, M.R. and Johnson, D.S. (1979) Computers and Intractability: A Guide to the Theory of NP-Completeness. W. H. Freeman.
Howard, M., Pincus, J. and Wing, J.M. (2005) Measuring Relative Attack Surfaces. In: Lee, D.T., Shieh, S.P. and Tygar, J.D., Eds., Computer Security in the 21 st Century , Springer-Verlag, 109-137. https://doi.org/10.1007/0-387-24006-3_8
Manadhata, P.K. and Wing, J.M. (2011) An Attack Surface Metric. IEEE Transactions on Software Engineering , 37, 371-386. https://doi.org/10.1109/tse.2010.60
AbuseIPDB (2024) Community-Driven IP Address Abuse Reporting and Reputation Database. Marathon Studios Inc. https://www.abuseipdb.com/
The Spamhaus Project (2024) Don’t Route or Peer (DROP) and Extended DROP (EDROP) Lists. The Spamhaus Project. https://www.spamhaus.org/drop/
Husari, G., Al-Shaer, E., Ahmed, M., Chu, B. and Niu, X. (2017) TTPDrill: Automatic and Accurate Extraction of Threat Actions from Unstructured Text of CTI Sources. Proceedings of the 33 rd Annual Computer Security Applications Conference , Orlando, 4-8 December 2017, 103-115. https://doi.org/10.1145/3134600.3134646
Papernot, N., McDaniel, P., Sinha, A. and Wellman, M. (2016) Towards the Science of Security and Privacy in Machine Learning. arXiv: 1611.03814.
Ferrag, M.A., Battah, A., Tihanyi, N., Debbah, M., Lestable, T. and Nzume, L.C. (2025) Revolutionizing Cyber Threat Detection with Large Language Models: A Privacy-Preserving AdaBoost-Based LLM Approach. IEEE Access , 13, 1-19.
Motlagh, F.H., Uhm, M., Chu, B., Niu, X. and Al-Shaer, E. (2024) Large Language Models in Cybersecurity: State-of-the-Art. arXiv: 2402.00891.
Weidinger, L., Uesato, J., Rauh, M., Griffin, C., Huang, P., Mellor, J., et al. (2022) Taxonomy of Risks Posed by Language Models. 2022 ACM Conference on Fairness Accountability and Transparency , Seoul, 21-24 June 2022, 214-229. https://doi.org/10.1145/3531146.3533088
Scarfone, K. and Mell, P. (2007) Guide to Intrusion Detection and Prevention Systems (IDPS). NIST Special Publication 800-94, National Institute of Standards and Technology.
National Institute of Standards and Technology (2024) The NIST Cybersecurity Framework 2.0. Technical Report, National Institute of Standards and Technology.
Athena Security Group (2026) Athena Core. Athena Security Group.
Athena Security Group (2026) Athena AI Analyst (Pallas). Athena Security Group.
Hassan, W.U., Noureddine, M.A., Datta, P. and Bates, A. (2020) OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-Layer Log Analysis. Proceedings 2020 Network and Distributed System Security Symposium , San Diego, 23-26 February 2020, 1-8. https://doi.org/10.14722/ndss.2020.24270
Wolsey, L.A. (1998) Integer Programming. Wiley.
McGregor, A. (2014) Graph Stream Algorithms: A Survey. ACM SIGMOD Record , 43, 9-20. https://doi.org/10.1145/2627692.2627694