United States

DoD Zero Trust Reference Architecture

45 controls. 4 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

45 controls 4 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

DoD Zero Trust Reference Architecture Evidence & Implementation Kit

45 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
DODZT-1.1User Inventory2
DODZT-1.2Conditional User Access0
DODZT-1.3Multi-Factor Authentication2
DODZT-1.4Privileged Access Management2
DODZT-1.5Identity Federation and User Credentialing0
DODZT-1.6Behavioral, Contextual ID, and Biometrics0
DODZT-1.7Least Privileged Access1
DODZT-1.8Continuous Authentication1
DODZT-1.9Integrated ICAM Platform0
DODZT-2.1Device Inventory2
DODZT-2.2Device Detection and Compliance0
DODZT-2.3Device Authorization with Real-Time Inspection0
DODZT-2.4Remote Access0
DODZT-2.5Partially and Fully Automated Asset, Vulnerability and Patch Management1
DODZT-2.6Unified Endpoint Management and Mobile Device Management0
DODZT-2.7Endpoint and Extended Detection and Response1
DODZT-3.1Application Inventory1
DODZT-3.2Secure Software Development and Integration0
DODZT-3.3Software Risk Management0
DODZT-3.4Resource Authorization and Integration0
DODZT-3.5Continuous Monitoring and Ongoing Authorizations1
DODZT-4.1Data Catalog Risk Alignment0
DODZT-4.2DoD Enterprise Data Governance0
DODZT-4.3Data Labeling and Tagging0
DODZT-4.4Data Monitoring and Sensing0
DODZT-4.5Data Encryption and Rights Management1
DODZT-4.6Data Loss Prevention0
DODZT-4.7Data Access Control1
DODZT-5.1Data Flow Mapping1
DODZT-5.2Software Defined Networking0
DODZT-5.3Macro Segmentation1
DODZT-5.4Micro Segmentation1
DODZT-6.1Policy Decision Point and Policy Orchestration1
DODZT-6.2Critical Process Automation0
DODZT-6.3Machine Learning0
DODZT-6.4Artificial Intelligence0
DODZT-6.5Security Orchestration, Automation and Response0
DODZT-6.6API Standardization0
DODZT-6.7Security Operations Center and Incident Response1
DODZT-7.1Log All Traffic2
DODZT-7.2Security Information and Event Management0
DODZT-7.3Common Security and Risk Analytics0
DODZT-7.4User and Entity Behavior Analytics1
DODZT-7.5Threat Intelligence Integration0
DODZT-7.6Automated Dynamic Policies1

Tell me when DoD Zero Trust Reference Architecture files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Global Admin inventory (target less than 5)
  • Privileged role assignment review
  • Break-glass account procedure
  • ABAC or policy-as-code repository
  • JIT access requests
  • Access reviews

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for DoD Zero Trust Reference Architecture, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition