Use when implementing device posture assessment as a zero trust access
Scanned 9/8/2026
Install to Claude Code
npx -y skills add oyi77/1ai-skills --skill implementing-device-posture-assessment-in-zero-trust --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Implementing Device Posture Assessment In Zero Trust?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/oyi77-implementing-device-posture-assessment-in-zero-tru)More formats (shields.io, HTML) on the badges page.
---
name: implementing-device-posture-assessment-in-zero-trust
description: Use when implementing device posture assessment as a zero trust access
control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune,
and Jamf into conditional access policies that enforce compliance before granting
resource access. . Use when working with implementing device posture assessment
in zero trust.
domain: cybersecurity
tags:
- device-posture
- zero-trust
- endpoint-compliance
- crowdstrike-zta
- intune
- conditional-access
- jamf
subdomain: zero-trust-architecture
version: '1.0'
author: oyi77
license: Apache-2.0
nist_csf:
- PR.AA-01
- PR.AA-05
- PR.IR-01
- GV.PO-01
category: cybersecurity
---
# Implementing Device Posture Assessment In Zero Trust
## Overview
Cybersecurity skill for implementing device posture assessment in zero trust. Follows industry best practices and security standards.
## When to Use
**Trigger phrases:**
- "implementing device posture assessment in zero trust"
- "Implementing device posture assessment as a zero trust access control by integra"
- When enforcing device health as a prerequisite for accessing corporate applications
- When integrating CrowdStrike ZTA scores, Intune compliance, or Jamf device status into access decisions
- When implementing CISA Zero Trust Maturity Model device pillar requirements
- When building conditional access policies that adapt based on real-time endpoint security posture
- When detecting and blocking access from compromised, unmanaged, or non-compliant devices
**Do not use** for IoT or headless devices that cannot run posture agents, as a standalone security control without identity verification, or when real-time posture data is unavailable and stale compliance data would create false trust.
## When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
## Prerequisites
- Endpoint Detection and Response (EDR): CrowdStrike Falcon with ZTA module, or Microsoft Defender for Endpoint
- Mobile Device Management (MDM): Microsoft Intune, Jamf Pro, or VMware Workspace ONE
- Identity Provider: Microsoft Entra ID, Okta, or Ping Identity with conditional access capability
- ZTNA Platform: Zscaler ZPA, Cloudflare Access, Palo Alto Prisma Access, or cloud-native IAP
- API access to EDR/MDM platforms for posture signal ingestion
## Workflow
```python
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
```
1. **Assess Requirements** — Evaluate current environment and define device posture assessment in zero trust implementation requirements.
2. **Design Architecture** — Plan the device posture assessment in zero trust architecture, including components, integrations, and data flows.
3. **Configure Components** — Set up and configure each device posture assessment in zero trust component according to best practices.
4. **Test Integration** — Validate that all components work together. Run functional and security tests.
5. **Deploy to Production** — Roll out the implementation with monitoring and rollback capabilities.
6. **Validate and Document** — Verify the implementation meets requirements. Document configuration and runbooks.
## Tools
- **Configuration Management** — Infrastructure as code and automation
- **Monitoring Stack** — Observability and alerting
- **Documentation Platform** — Runbooks and architecture docs
## Process
1. **Prepare** — Gather requirements, verify prerequisites, set up environment
1. **Execute** — Run implementing device posture assessment in zero trust workflow with configured parameters
1. **Verify** — Validate output meets requirements, document results
## Verification
- [ ] All device posture assessment in zero trust procedures executed completely and documented
- [ ] Findings validated against multiple data sources
- [ ] False positives identified and filtered
- [ ] Results documented with evidence and timestamps
- [ ] Recommendations provided with risk-based prioritization
## Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!