Architecture paradigm / SP 800-207 final 2020-08-11

NIST SP 800-207 Zero Trust Architecture

NIST SP 800-207, Zero Trust Architecture, final 11 August 2020, is an architecture paradigm for protecting resources. Authentication and authorization are discrete decisions before a session to a resource is established. Network location and asset ownership do not grant implicit trust. This card is SP 800-207. SP 800-207A is a separate companion.

Architecture paradigmSP 800-207 final 2020-08-11Last reviewed

What it helps you do

Read SP 800-207 as principles for protecting resources: assets, services, workflows, and accounts. A session to YardOS still needs a subject, an action, and an authorization decision. Presence on the warehouse VLAN is a location, and location is not that decision.

A useful way to begin

  1. Pin the edition before you quote it: SP 800-207 final, 11 August 2020, DOI 10.6028/NIST.SP.800-207.
  2. Read the core claim in plain language: no implicit trust from network location or asset ownership. Authentication and authorization are discrete before a session to a resource.
  3. Name the resources you mean (YardOS, the export workflow, the vendor account). A VLAN, a VPN, or a product name is not the resource list.
  4. Rewrite a vendor sentence until it names the resource, the policy decision, and who owns that decision.

What good evidence looks like

For one synthetic system, a resource inventory plus a named owner of the policy decision point. Example: YardOS diagnostic actions for a scanner vendor, scoped to two hours, with Maya as the decision owner. A purchase order that says “we bought ZTNA” is not that record.

Other records you might already have

  • A one-page inventory of YardOS resources (the diagnostic API, the admin account, the export job) with an owner for each.
  • A note that names who owns the policy decision for a scanner vendor’s two-hour window, including when that window expires.

Labeled companions

  • SP 800-207A. Separate companion (final September 2023). Not this document and not a substitute for SP 800-207.

Claims to retire

Buy zero trust.

SP 800-207 (final 2020-08-11) is an architecture paradigm. A purchase is not the architecture.

A ZTNA appliance means zero trust architecture is complete.

A ZTNA product can be one control. It does not finish the principles in SP 800-207.

An internal IP address is trusted.

SP 800-207 does not treat network location, including an internal address, as enough trust for a resource.

Related lessons

This is an original educational guide. Use the publisher’s official materials for the authoritative requirements and licensing terms. A relationship between maps is not one-to-one control equivalence. This card complements the six live maps. It is not a row in that comparison.

Find your next idea.

Tip: press / to open search. Escape closes this window.