TrustSec uses Security Group Tags (SGTs) to provide endpoint entitlement in an enterprise network. SGTs are used to enforce access control policies based on user identity and group membership, rather than relying on traditional access control lists (ACLs)5678. References: Understanding Cisco TrustSec5.