SP800-207-2.1 | Tenet 1: All Data Sources and Computing Services as Resources | 1 |
SP800-207-2.2 | Tenet 2: All Communication Secured Regardless of Network | 1 |
SP800-207-2.3 | Tenet 3: Per Session Resource Access | 2 |
SP800-207-2.4 | Tenet 4: Dynamic Policy Driven Access | 2 |
SP800-207-2.5 | Tenet 5: Monitor Integrity and Posture of Assets | 1 |
SP800-207-2.6 | Tenet 6: Dynamic Authentication and Authorization | 2 |
SP800-207-2.7 | Tenet 7: Telemetry to Improve Posture | 1 |
SP800-207-3.1 | Policy Engine Capabilities | 2 |
SP800-207-3.2 | Policy Administrator Role | 0 |
SP800-207-3.3 | Policy Enforcement Point Coverage | 1 |
SP800-207-3.4 | Continuous Diagnostics and Mitigation Inputs | 1 |
SP800-207-3.5 | Identity Management Integration | 2 |
SP800-207-4.1 | Enhanced Identity Governance Deployment | 1 |
SP800-207-4.2 | Micro Segmentation Deployment | 1 |
SP800-207-4.3 | Software Defined Perimeter Deployment | 1 |
SP800-207-5.1 | Trust Algorithm Documentation | 0 |
SP800-207-6.1 | ZTA Threats and Mitigations | 0 |
SP800-207-7.1 | Migration Strategy and Roadmap | 0 |
SP800-207-7.2 | Interoperability with Existing Controls | 0 |
SP800-207-DEP-AGENT | Device Agent/Gateway-Based Deployment | 2 |
SP800-207-DEP-ENCLAVE | Enclave-Based Deployment | 2 |
SP800-207-DEP-PORTAL | Resource Portal-Based Deployment | 2 |
SP800-207-DEP-SANDBOX | Device Application Sandboxing | 1 |
SP800-207-MIG-ACTORS | Migration Step: Identify Actors on the Enterprise | 2 |
SP800-207-MIG-ASSETS | Migration Step: Identify Assets Owned by the Enterprise | 2 |
SP800-207-MIG-DEPLOY | Migration Step: Identify Candidate Solutions, Deploy, and Expand | 1 |
SP800-207-MIG-POLICY | Migration Step: Formulate Policies for the ZTA Candidate | 2 |
SP800-207-MIG-PROCESS | Migration Step: Identify Key Processes and Evaluate Risks | 2 |
SP800-207-NET-REQ | Network Requirements to Support ZTA | 2 |
SP800-207-SC-CONTRACTED | Deployment Scenario: Contracted Services and Nonemployee Access | 1 |
SP800-207-SC-CROSSENT | Deployment Scenario: Collaboration Across Enterprise Boundaries | 1 |
SP800-207-SC-MULTICLOUD | Deployment Scenario: Multi-cloud / Cloud-to-Cloud Enterprise | 2 |
SP800-207-SC-PUBLIC | Deployment Scenario: Public- or Customer-Facing Services | 1 |
SP800-207-SC-SATELLITE | Deployment Scenario: Enterprise with Satellite Facilities | 1 |
SP800-207-SUP-CDM | Continuous Diagnostics and Mitigation (CDM) System | 3 |
SP800-207-SUP-COMPLY | Industry Compliance System | 1 |
SP800-207-SUP-DAP | Data Access Policies | 2 |
SP800-207-SUP-IDM | Identity Management System | 3 |
SP800-207-SUP-LOGS | Network and System Activity Logs | 1 |
SP800-207-SUP-PKI | Enterprise Public Key Infrastructure (PKI) | 2 |
SP800-207-SUP-SIEM | Security Information and Event Management (SIEM) System | 1 |
SP800-207-SUP-THREAT | Threat Intelligence Feeds | 1 |
SP800-207-TA-CONTEXT | Singular vs Contextual Trust Algorithm | 1 |
SP800-207-TA-CRITERIA | Criteria-Based vs Score-Based Trust Algorithm | 1 |
SP800-207-THR-CREDS | Threat: Stolen Credentials and Insider Threat | 2 |
SP800-207-THR-DOS | Threat: Denial-of-Service or Network Disruption | 1 |
SP800-207-THR-NPE | Threat: Use of Non-Person Entities (NPE) in ZTA Administration | 2 |
SP800-207-THR-PROPRIETARY | Threat: Reliance on Proprietary Data Formats or Solutions | 1 |
SP800-207-THR-STORAGE | Threat: Storage of System and Network Information | 1 |
SP800-207-THR-SUBVERT | Threat: Subversion of ZTA Decision Process | 1 |
SP800-207-THR-VISIBILITY | Threat: Limited Visibility on the Network | 1 |