# Zero Trust & Modern Access Certificate Program

Canonical URL: <https://www.graduateschool.edu/certificates/zero-trust-and-modern-access-certificate-program>

## Overview

This certificate traces the modern access problem from the credential through to the authorization boundary. It opens at the identity layer and runs the chain in order — identity, proofing, authentication and MFA, authorization, federation, and the access decision itself — weighted toward multifactor authentication, since most federal compromises begin with a credential rather than an exploit. Multifactor is pulled apart rather than treated as a checkbox: authenticator types separated, assurance levels explained, and the attacks aimed directly at MFA covered in detail, so participants can articulate why a push notification and a PIV card are not equivalent controls.

The path then turns architectural, and finally operational. Zero trust moves from principle to plan through a current-state maturity assessment using the CISA Zero Trust Maturity Model, then the pillars in sequence — identity and access modernization, device, network and workload trust enforcement, and application, data and policy enforcement — followed by the visibility, analytics and automation that make zero trust operational, and a staged implementation roadmap carrying governance and metrics. It closes on federal cloud authorization and how it is changing, working through the transition from FedRAMP Rev5 to the 20x model and CR26, so the access architecture is understood together with the authorization regime it has to satisfy.

## What you'll learn

- Distinguish identity, account, credential, and authenticator, and explain how identity, authentication, authorization, and access relate to each other; Explain identity proofing and the joiner, mover, and leaver lifecycle
- Apply the assurance-level model, IAL, AAL, and FAL, to real access situations; Compare common MFA methods and explain why stronger methods provide greater assurance
- Recognize attacks aimed at MFA, including phishing, MFA fatigue, credential theft, and adversary-in-the-middle; Apply least privilege, need-to-know, role-based access control, and attribute-based access control to authorization decisions
- Explain federation and single sign-on, including identity providers, relying parties, credentials, and assertions; Explain zero trust principles and the federal drivers behind them
- Assess current-state maturity using the CISA ZT Maturity Model; Modernize identity, credential, and access management
- Enforce trust across devices, networks, and workloads; Architect application, data, and policy enforcement
- Apply visibility, analytics, and automation for threat response; Build a staged zero trust implementation roadmap
- Work the transition in federal cloud authorization from FedRAMP Rev5 to the 20x model and CR26

## Curriculum
1. **ICAM and MFA Fundamentals Course**
2. **Zero Trust Architecture Implementation**
3. **FedRAMP Modernization: Transitioning from Rev5 to 20x & CR26**
4. **Cryptography Essentials Course**

## Pricing

**Tuition:** $2199
