Zero Trust for public bodies, starting with identity.
F Creative Studio 360 helps agencies in any country move toward Zero Trust without replacing every system first. The architectural reference is NIST SP 800-207. An Australian mandate is added only when that agency is subject to it.
Verify, then allow. In stages.
NIST SP 800-207 describes Zero Trust as a way of deciding access from identity, device, and the sensitivity of the data, rather than from a network location. That model is used by public bodies in any country.
Where an Australian government entity is subject to the Protective Security Policy Framework, Zero Trust expectations in that framework are included. The Information Security Manual remains the technical control language for those entities. F Creative Studio 360 does not certify an architecture.
- Identity is the first phase
- Multi-factor authentication and tighter admin access can start before legacy applications are rebuilt.
- Legacy can stay, for a time
- A gateway in front of an old application is a legitimate step. It is not the finished architecture.
- The mandate is local
- A PSPF requirement is not applied to a government that is not subject to the PSPF.
- This is not a product rollout
- We do not require a named Zero Trust product. The design uses what the agency already has, plus what it agrees to add.
What the design covers
A roadmap is phased so a public service keeps running.
- Identity
- Who is asking, how sure you are, and whether the privilege matches the job.
- Device
- Whether the device is known and healthy enough for the data it wants.
- Network place
- Access that does not treat the office network as trusted.
- Data and monitoring
- Which information is sensitive, and how an odd request is seen.
How an engagement runs
Agencies with staff and systems in more than one country can phase the work by entity.
- 1
Read the current paths
How staff, vendors and citizens reach systems today.
- 2
Name the rule
NIST SP 800-207 for the architecture. PSPF or ISM only when they bind.
- 3
Sequence the change
Identity first, unless the agency has a sharper constraint.
- 4
Leave implementation owned
Building the controls is in scope only when it is written in.
What you receive
- A current-state note against Zero Trust principles.
- A phased roadmap the agency can fund.
- A record of which government rule was in scope.
- No claim that the architecture is certified.
What this is not
This is not a penetration test, and it is not a promise that legacy systems disappear in the first phase.
Common questions
Do we have to follow the Australian PSPF?+
Only if that framework applies to you. Everyone else can use NIST SP 800-207 as the architecture, and their own government’s baseline beside it.
Will you replace our legacy systems?+
Not as the first step. Access can be tightened around them. Replacement is a separate decision.
Where do you deliver this?+
For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.
How much does it cost, and how long does it take?+
It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Start with who is allowed in.
F Creative Studio 360 will look at identity and the systems citizens depend on, then say what the first phase includes.
