top of page


Risk-Based Dynamic Access Rules: Meeting CISA ZTMM Conditional Access Requirements Under OMB M-22-09
Most civilian agencies still have a practical problem at the access layer: users are granted access based on static roles, but the risk around that user changes throughout the day. The user may move from a managed laptop to an unmanaged device. The session may originate from an unusual location. The endpoint may fall out of compliance. The account may show abnormal behavior. If the access decision does not change when the risk changes, the agency is not operating at OMB M-22-
Jun 297 min read


DTM 25-003 User Access Requirements: Building Risk-Based Dynamic Access Rules for DoD Zero Trust Implementation
Dynamic access control requires that authorization decisions must move beyond static role-based access and account for current risk conditions. This blog explores the right sequence to implement this correctly for DTM 25-003.
Jun 227 min read
bottom of page
