Cisco TrustSec uses Security Group Tags (SGTs) to enforce access control policies across the network. SGTs are assigned to traffic at ingress points, and these tags are then used to make policy decisions as the traffic moves through the network. This allows for consistent policy enforcement regardless of the location of the user or device, making it scalable and secure. References: Implementing Cisco TrustSec (as part of Cisco's CCNP Security certification)