NIST SP 800-207 logical ZTA

securityv1

/01 Views

Control plane - PE and PA with trust signalssecurity
Request path - subject, PEP and resourcesecurity
Decision, enforcement and assurancesecurity

/02 About

Model policy engine, policy administrator, enforcement point, subject and resource with independent control/data paths

An Arq semantic interpretation of NIST SP 800-207 section 3, separating the policy engine, policy administrator, policy enforcement point, requesting subject, enterprise resource and contextual inputs. The policy engine evaluates policy and signals. The policy administrator establishes or terminates access according to decisions. The enforcement point mediates the subject-resource data path and emits security evidence. Control decisions and protected data are separate concerns. Source: https://csrc.nist.gov/pubs/sp/800/207/final. This is not an official NIST diagram and does not imply certification.

Published by Lattix · 12 elements · 12 relationships · validated on publish

/03 Contents

Business Actor
Access subject
Application Component
Identity evidence, Device health signal, Threat intelligence, Policy engine, Policy administrator, Policy enforcement point, Continuous diagnostics, Security event analytics
Application
Enterprise resource
Data Store
Access policy
Role
Resource owner