Zero Trust
Focuses on protecting resources to design enterprise infrastructure and not network segments or location. Assumes no implicit trust based on physical or network location. Performs authentication and authorization as distinct tasks before a session is established.
Secure by design
app developed with security integrated into the entire SDLC
Secure by deployment
app deployed into an environment where security is considered in the network and system design
Secure by default
app design assumed natively secure