The company formally adopts the principle that no user or device is trusted by default regardless of network location
Sekit's Zero Trust network access policy is a topic-specific policy under A.5.1 that grants access per request based on verified identity and device state, never on network location.
Granting access per request based on verified identity and device state rather than network location is a stricter, explicit form of the access control A.5.15 requires.