United States

NIST SP 800-207

51 controls. 5 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

51 controls 5 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NIST SP 800-207 Zero Trust Architecture Evidence & Implementation Kit

51 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
SP800-207-2.1Tenet 1: All Data Sources and Computing Services as Resources1
SP800-207-2.2Tenet 2: All Communication Secured Regardless of Network1
SP800-207-2.3Tenet 3: Per Session Resource Access2
SP800-207-2.4Tenet 4: Dynamic Policy Driven Access2
SP800-207-2.5Tenet 5: Monitor Integrity and Posture of Assets1
SP800-207-2.6Tenet 6: Dynamic Authentication and Authorization2
SP800-207-2.7Tenet 7: Telemetry to Improve Posture1
SP800-207-3.1Policy Engine Capabilities2
SP800-207-3.2Policy Administrator Role0
SP800-207-3.3Policy Enforcement Point Coverage1
SP800-207-3.4Continuous Diagnostics and Mitigation Inputs1
SP800-207-3.5Identity Management Integration2
SP800-207-4.1Enhanced Identity Governance Deployment1
SP800-207-4.2Micro Segmentation Deployment1
SP800-207-4.3Software Defined Perimeter Deployment1
SP800-207-5.1Trust Algorithm Documentation0
SP800-207-6.1ZTA Threats and Mitigations0
SP800-207-7.1Migration Strategy and Roadmap0
SP800-207-7.2Interoperability with Existing Controls0
SP800-207-DEP-AGENTDevice Agent/Gateway-Based Deployment2
SP800-207-DEP-ENCLAVEEnclave-Based Deployment2
SP800-207-DEP-PORTALResource Portal-Based Deployment2
SP800-207-DEP-SANDBOXDevice Application Sandboxing1
SP800-207-MIG-ACTORSMigration Step: Identify Actors on the Enterprise2
SP800-207-MIG-ASSETSMigration Step: Identify Assets Owned by the Enterprise2
SP800-207-MIG-DEPLOYMigration Step: Identify Candidate Solutions, Deploy, and Expand1
SP800-207-MIG-POLICYMigration Step: Formulate Policies for the ZTA Candidate2
SP800-207-MIG-PROCESSMigration Step: Identify Key Processes and Evaluate Risks2
SP800-207-NET-REQNetwork Requirements to Support ZTA2
SP800-207-SC-CONTRACTEDDeployment Scenario: Contracted Services and Nonemployee Access1
SP800-207-SC-CROSSENTDeployment Scenario: Collaboration Across Enterprise Boundaries1
SP800-207-SC-MULTICLOUDDeployment Scenario: Multi-cloud / Cloud-to-Cloud Enterprise2
SP800-207-SC-PUBLICDeployment Scenario: Public- or Customer-Facing Services1
SP800-207-SC-SATELLITEDeployment Scenario: Enterprise with Satellite Facilities1
SP800-207-SUP-CDMContinuous Diagnostics and Mitigation (CDM) System3
SP800-207-SUP-COMPLYIndustry Compliance System1
SP800-207-SUP-DAPData Access Policies2
SP800-207-SUP-IDMIdentity Management System3
SP800-207-SUP-LOGSNetwork and System Activity Logs1
SP800-207-SUP-PKIEnterprise Public Key Infrastructure (PKI)2
SP800-207-SUP-SIEMSecurity Information and Event Management (SIEM) System1
SP800-207-SUP-THREATThreat Intelligence Feeds1
SP800-207-TA-CONTEXTSingular vs Contextual Trust Algorithm1
SP800-207-TA-CRITERIACriteria-Based vs Score-Based Trust Algorithm1
SP800-207-THR-CREDSThreat: Stolen Credentials and Insider Threat2
SP800-207-THR-DOSThreat: Denial-of-Service or Network Disruption1
SP800-207-THR-NPEThreat: Use of Non-Person Entities (NPE) in ZTA Administration2
SP800-207-THR-PROPRIETARYThreat: Reliance on Proprietary Data Formats or Solutions1
SP800-207-THR-STORAGEThreat: Storage of System and Network Information1
SP800-207-THR-SUBVERTThreat: Subversion of ZTA Decision Process1
SP800-207-THR-VISIBILITYThreat: Limited Visibility on the Network1

Tell me when NIST SP 800-207 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for NIST SP 800-207, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition