# Zero Trust & Modern Access Certificate Program (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/certificates/zero-trust-and-modern-access-certificate-program-self-paced>

## Overview

This certificate follows the modern access problem from the credential all the way to the authorization boundary. It starts at the identity layer, running the chain in order — identity, proofing, authentication and MFA, authorization, federation, and finally the access decision itself — with particular weight on multifactor authentication, because most federal compromises start with a credential rather than an exploit. Rather than treating multifactor as a single checkbox, it separates the authenticator types, explains the assurance levels behind them, and covers the attacks aimed squarely at MFA, so learners come away able to say why a push notification and a PIV card are not equivalent controls.

From there it becomes architectural and then operational. Zero trust moves from principle to plan: a current-state maturity assessment using the CISA Zero Trust Maturity Model, then the pillars in turn — identity and access modernization, device, network and workload trust enforcement, and application, data and policy enforcement — followed by the visibility, analytics and automation that make zero trust real, and a staged implementation roadmap with governance and metrics attached. The path closes on federal cloud authorization and how it is changing, covering the transition from FedRAMP Rev5 to the 20x model and CR26, so the access architecture is understood alongside the authorization regime it has to satisfy.

## What you'll learn

- Distinguish identity, account, credential, and authenticator, and explain how identity, authentication, authorization, and access relate to each other; Explain identity proofing and the joiner, mover, and leaver lifecycle
- Apply the assurance-level model, IAL, AAL, and FAL, to real access situations; Compare common MFA methods and explain why stronger methods provide greater assurance
- Recognize attacks aimed at MFA, including phishing, MFA fatigue, credential theft, and adversary-in-the-middle; Apply least privilege, need-to-know, role-based access control, and attribute-based access control to authorization decisions
- Explain federation and single sign-on, including identity providers, relying parties, credentials, and assertions; Explain zero trust principles and the federal drivers behind them
- Assess current-state maturity using the CISA ZT Maturity Model; Modernize identity, credential, and access management
- Enforce trust across devices, networks, and workloads; Architect application, data, and policy enforcement
- Apply visibility, analytics, and automation for threat response; Build a staged zero trust implementation roadmap
- Work the transition in federal cloud authorization from FedRAMP Rev5 to the 20x model and CR26

## Curriculum
1. **ICAM and MFA Fundamentals Course (Self-Paced)**
2. **Zero Trust Architecture Implementation (Self-Paced)**
3. **FedRAMP Modernization: Transitioning from Rev5 to 20x & CR26 (Self-Paced)**
4. **Cryptography Essentials Course (Self-Paced)**

## Pricing

**Tuition:** $2199
