NIST SP 800-207

NIST’s Reference Architecture for Zero Trust

What is NIST SP 800-207?

NIST SP 800-207, Zero Trust Architecture, defines NIST’s logical model for applying Zero Trust to enterprise resources. NIST SP 800-207 architecture assumes no implicit trust based solely on network location or ownership and separates the general Zero Trust concept from a specific reference architecture for policy-driven access.

The model describes a policy engine that makes access decisions, a policy administrator that establishes or ends communication paths, and policy enforcement points that enable and monitor connections. A trust algorithm evaluates identity, device posture, resource context, threat intelligence, and other data sources within logical deployment models rather than prescribing one product topology.

What is NIST SP 800-207 used for?

Organizations use the publication to design explicit access decisions, continuous verification, segmentation, telemetry, and identity- and device-aware policy. It helps architects map policy components to existing identity, endpoint, network, and application services while identifying where enforcement, logging, and decision data must remain reliable under operational conditions.

For leaders, it provides a governance reference connecting Zero Trust, Access Control, the Principle of Least Privilege, and Multi-Factor Authentication. It is not a product blueprint or compliance mandate: architecture choices, migration sequence, assurance, and metrics must reflect business processes, legacy constraints, threat models, and the organization’s capacity to operate policy consistently.

Continue reading

NIST SP 800-215
Guidance for a Secure Enterprise Network Landscape
NIST SP 800-160
Engineering Trustworthy Secure Systems
ISO/IEC 27001
Information Security Management System Standard

Please note!
Any use of this website requires prior agreement to our Terms of Use, Privacy Policy, and Cookie Policy.
If you do not fully agree to all of them, do not use this website.