Back to Frameworks

NIST SP 800-207

United States
v2020
13 domains
51 controls

Zero Trust Architecture

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (13)

Deployment Models

3 controls
Controls in the Deployment Models domain of NIST SP 800-2073 controls
CodeTitle
SP800-207-4.1Enhanced Identity Governance Deployment
SP800-207-4.2Micro Segmentation Deployment
SP800-207-4.3Software Defined Perimeter Deployment

Foundational Tenets

7 controls
Controls in the Foundational Tenets domain of NIST SP 800-2077 controls
CodeTitle
SP800-207-2.1Tenet 1: All Data Sources and Computing Services as Resources
SP800-207-2.2Tenet 2: All Communication Secured Regardless of Network
SP800-207-2.3Tenet 3: Per Session Resource Access
SP800-207-2.4Tenet 4: Dynamic Policy Driven Access
SP800-207-2.5Tenet 5: Monitor Integrity and Posture of Assets
SP800-207-2.6Tenet 6: Dynamic Authentication and Authorization
SP800-207-2.7Tenet 7: Telemetry to Improve Posture

Logical Components

3 controls
Controls in the Logical Components domain of NIST SP 800-2073 controls
CodeTitle
SP800-207-3.1Policy Engine Capabilities
SP800-207-3.2Policy Administrator Role
SP800-207-3.3Policy Enforcement Point Coverage

NIST SP 800-207: Access Control

5 controls

Logical and physical access controls (NIST SP 800-207)

Controls in the NIST SP 800-207: Access Control domain of NIST SP 800-2075 controls
CodeTitle
SP800-207-DEP-PORTALResource Portal-Based Deployment
SP800-207-DEP-SANDBOXDevice Application Sandboxing
SP800-207-NET-REQNetwork Requirements to Support ZTA
SP800-207-TA-CONTEXTSingular vs Contextual Trust Algorithm
SP800-207-TA-CRITERIACriteria-Based vs Score-Based Trust Algorithm

NIST SP 800-207: Asset Management

5 controls

Information asset management (NIST SP 800-207)

Controls in the NIST SP 800-207: Asset Management domain of NIST SP 800-2075 controls
CodeTitle
SP800-207-DEP-AGENTDevice Agent/Gateway-Based Deployment
SP800-207-DEP-ENCLAVEEnclave-Based Deployment
SP800-207-SUP-IDMIdentity Management System
SP800-207-SUP-PKIEnterprise Public Key Infrastructure (PKI)
SP800-207-SUP-SIEMSecurity Information and Event Management (SIEM) System

NIST SP 800-207: Communications Security

5 controls

Network and communications security (NIST SP 800-207)

Controls in the NIST SP 800-207: Communications Security domain of NIST SP 800-2075 controls
CodeTitle
SP800-207-MIG-ACTORSMigration Step: Identify Actors on the Enterprise
SP800-207-MIG-ASSETSMigration Step: Identify Assets Owned by the Enterprise
SP800-207-MIG-POLICYMigration Step: Formulate Policies for the ZTA Candidate
SP800-207-MIG-PROCESSMigration Step: Identify Key Processes and Evaluate Risks
SP800-207-THR-NPEThreat: Use of Non-Person Entities (NPE) in ZTA Administration

NIST SP 800-207: Cryptography

5 controls

Cryptographic controls (NIST SP 800-207)

Controls in the NIST SP 800-207: Cryptography domain of NIST SP 800-2075 controls
CodeTitle
SP800-207-SC-CONTRACTEDDeployment Scenario: Contracted Services and Nonemployee Access
SP800-207-SC-CROSSENTDeployment Scenario: Collaboration Across Enterprise Boundaries
SP800-207-SC-MULTICLOUDDeployment Scenario: Multi-cloud / Cloud-to-Cloud Enterprise
SP800-207-SC-PUBLICDeployment Scenario: Public- or Customer-Facing Services
SP800-207-SC-SATELLITEDeployment Scenario: Enterprise with Satellite Facilities

NIST SP 800-207: Information Security Policies

5 controls

Organizational information security policies (NIST SP 800-207)

Controls in the NIST SP 800-207: Information Security Policies domain of NIST SP 800-2075 controls
CodeTitle
SP800-207-SUP-CDMContinuous Diagnostics and Mitigation (CDM) System
SP800-207-SUP-COMPLYIndustry Compliance System
SP800-207-SUP-DAPData Access Policies
SP800-207-SUP-LOGSNetwork and System Activity Logs
SP800-207-SUP-THREATThreat Intelligence Feeds

NIST SP 800-207: Operations Security

6 controls

Secure operations and monitoring (NIST SP 800-207)

Controls in the NIST SP 800-207: Operations Security domain of NIST SP 800-2076 controls
CodeTitle
SP800-207-THR-CREDSThreat: Stolen Credentials and Insider Threat
SP800-207-THR-DOSThreat: Denial-of-Service or Network Disruption
SP800-207-THR-PROPRIETARYThreat: Reliance on Proprietary Data Formats or Solutions
SP800-207-THR-STORAGEThreat: Storage of System and Network Information
SP800-207-THR-SUBVERTThreat: Subversion of ZTA Decision Process
SP800-207-THR-VISIBILITYThreat: Limited Visibility on the Network

Programme Management

2 controls
Controls in the Programme Management domain of NIST SP 800-2072 controls
CodeTitle
SP800-207-7.1Migration Strategy and Roadmap
SP800-207-7.2Interoperability with Existing Controls

Risk

1 controls
Controls in the Risk domain of NIST SP 800-2071 controls
CodeTitle
SP800-207-6.1ZTA Threats and Mitigations

Supporting Components

3 controls
Controls in the Supporting Components domain of NIST SP 800-2073 controls
CodeTitle
SP800-207-3.4Continuous Diagnostics and Mitigation Inputs
SP800-207-3.5Identity Management Integration
SP800-207-MIG-DEPLOYMigration Step: Identify Candidate Solutions, Deploy, and Expand

Trust Algorithm

1 controls
Controls in the Trust Algorithm domain of NIST SP 800-2071 controls
CodeTitle
SP800-207-5.1Trust Algorithm Documentation

Your Compliance Coverage

If you comply with NIST SP 800-207, you already cover:

Maps to 9 other frameworks

51 total controls
NIST SP 800-53 Rev 5
32 source controls mapped|29 target controls covered
63%
NIST SP 800-171
28 source controls mapped|9 target controls covered
55%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
6 source controls mapped|3 target controls covered
12%
BRCGS Global Standard for Food Safety Issue 9
3 source controls mapped|2 target controls covered
6%
FedRAMP Rev 5
2 source controls mapped|1 target controls covered
4%
SWIFT CSCF
1 source controls mapped|1 target controls covered
2%
SWIFT CSCF v2024
1 source controls mapped|1 target controls covered
2%
ISO 19011
1 source controls mapped|1 target controls covered
2%
ISO 31000:2018
1 source controls mapped|1 target controls covered
2%

Frequently Asked Questions

What is NIST SP 800-207?

NIST SP 800-207 is a compliance framework from United States with 13 domains and 51 controls. Zero Trust Architecture It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-207 have?

NIST SP 800-207 has 51 controls organised across 13 domains. The largest domains are Foundational Tenets (7 controls), NIST SP 800-207: Operations Security (6 controls), NIST SP 800-207: Access Control (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-207 map to?

NIST SP 800-207 maps to 9 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (63% coverage), NIST SP 800-171 (55% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (12% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-207 compliance?

Start your NIST SP 800-207 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-207 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 51 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required