CARTA — Continuous Adaptive Risk & Trust Assessment | Secure In Security

Contact / About / Policy

Secure In Security · Risk Strategy Series

CARTA — Continuous Adaptive Risk & Trust Assessment

Security decisions that never stop deciding.

Doc ID SIS-CARTA-002 · Published · ~900 words

01Trust Is Not a One-Time Decision

Most security architectures still make their most important decision exactly once. A user authenticates, a device passes a compliance check, a firewall rule matches — and from that moment forward, access flows freely until something expires. The environment that decision was made in, however, never stops changing. Users travel, devices drift out of compliance, sessions get hijacked, and workloads spin up and disappear in seconds. An access decision that was correct at 9:02 a.m. can be actively dangerous by 9:15.

Gartner introduced Continuous Adaptive Risk and Trust Assessment (CARTA) in 2017 to confront exactly this problem. CARTA is a strategic posture, not a product: it holds that risk and trust are dynamic properties that must be evaluated continuously, with responses that adapt in proportion to what the evidence shows — across every session, transaction, and lifecycle stage.

02From Allow/Deny Gates to Continuous Risk Scoring

The traditional gate fails in two directions at once. Set it strict, and it blocks legitimate work, generating friction and shadow-IT. Set it permissive, and an attacker holding valid credentials walks through — and stays through, because the gate never looks back.

The Old Model — Binary Gate

Allow or deny, decided once at login. Correct for a moment; blind forever after.

The CARTA Model — Live Gradient

LowRisingCritical

allow → step-up MFA → reduce privilege → restrict → terminate

CARTA replaces the binary verdict with a living risk score. Every session carries a continuously recomputed score built from identity confidence, device health, behavioral consistency, and the sensitivity of the resource being touched. Analytics and user and entity behavior analytics (UEBA) supply the evidence; policy engines translate the score into action.

Context is the currency. A login from a managed laptop on a known network touching routine resources scores low and flows freely. The same account reaching for sensitive data from an unmanaged device on anonymizing infrastructure scores high — and the policy engine reacts before a human analyst ever sees an alert.

Responses become proportional rather than absolute. Instead of allow or deny, the system can allow, allow with step-up authentication, allow with reduced privilege, monitor more aggressively, restrict to read-only, or terminate the session outright. Low-risk activity proceeds without friction; rising risk meets rising resistance. The decision stops being a gate and becomes a gradient — one that moves as fast as the attacker does.

03How CARTA Complements Zero Trust Architecture

Zero Trust and CARTA are frequently conflated, but they answer different questions. Zero Trust is an architectural principle: never trust, always verify. It relocates the perimeter to identity, enforces least privilege, and microsegments the network so nothing is trusted by position.

Zero Trust asks whether a connection should be allowed. CARTA keeps asking. Without continuous assessment, a Zero Trust deployment can quietly regress into a very thorough one-time check — verified rigorously at the front door, then trusted for the rest of the session. CARTA supplies the operating philosophy that keeps verification alive: the continuous evaluation loop at the heart of NIST SP 800-207 is CARTA thinking rendered as architecture.

The pairing is concrete: Zero Trust policy enforcement points — identity providers, access proxies, and segmentation gateways — become the actuators through which CARTA’s continuously updated risk scores take effect, revoking or reshaping access mid-session instead of waiting for the next login.

CARTA also reaches further than run-time access. Gartner framed it across the full lifecycle — plan, build, and run — meaning the same adaptive mindset governs vendor risk, development pipelines, and supply-chain trust before anything reaches production. Zero Trust governs access; CARTA governs the lifecycle around it. Deployed together, Zero Trust provides the enforcement points and CARTA provides the judgment that flows through them.

04Applying Adaptive Assessment Across Users, Devices, and Workloads

Adaptive assessment only works when it covers every entity class that can carry risk. The matrix below shows how continuous signals, risk indicators, and proportional responses map across the three that matter most.

Entity Continuous Signals Risk Indicators Adaptive Responses
Users Authentication patterns, location, behavioral baselines, peer-group norms Impossible travel, off-hours bulk access, privilege-use anomalies Step-up MFA, session restriction, forced re-authentication
Devices Posture and patch level, EDR agent health, configuration state Jailbreak or root indicators, missing agent, compliance drift Conditional access, network quarantine, automated remediation
Workloads Service identity, API call behavior, IaC and runtime posture Anomalous east-west traffic, secret sprawl, drift from golden baseline Tighten microsegmentation, rotate credentials, isolate workload

The pattern is identical in every row: gather live signals, score them against a baseline, and respond in proportion. Users see step-up challenges only when their own behavior earns one. Devices lose access the moment posture drifts, and regain it the moment remediation lands. Workloads, increasingly the majority of identities in any cloud estate, get the same scrutiny humans do, with microsegmentation and credential rotation as the adaptive levers. Sessions get the same treatment: token binding, risk scoring, and mid-session revocation ensure a hijacked cookie cannot ride an old decision.

CARTA infographic: binary allow/deny gate versus continuous risk gradient with proportional responses, how CARTA complements Zero Trust across the plan-build-run lifecycle, and an adaptive assessment matrix covering users, devices, and workloads.
Fig. 1 — CARTA at a glance (SIS-CARTA-002 infographic)

05The Bottom Line

Static gates made sense when environments were static. They are not. CARTA turns security from a checkpoint into a control loop: continuously measure risk and trust, adapt the response, and verify the outcome, for every user, device, and workload, at every stage of the lifecycle. Pair it with Zero Trust enforcement and the result is an architecture that does not merely verify before trusting, but never stops verifying at all. In a world where conditions change by the minute, the only defensible decision is one you keep making.

Key Takeaway

Zero Trust asks whether a connection should be allowed. CARTA keeps asking , asuring risk and trust continuously and responding in proportion, so a decision that was right at login stays right for the whole session.