Date Published: December 21, 2022
Comments Due: February 6, 2023 (public comment period is CLOSED)
Email Questions to: nccoe-zta-project@list.nist.gov
The Zero Trust Architecture (ZTA) team at NIST's National Cybersecurity Center of Excellence (NCCoE) has published the second version of volumes A-D and the first version of volume E of a preliminary draft practice guide titled "Implementing a Zero Trust Architecture” and is seeking the public's comments on their contents.
This guide summarizes how the NCCoE and its collaborators are using commercially available technology to build interoperable, open standards-based ZTA example implementations that align to the concepts and principles in NIST Special Publication (SP) 800-207, Zero Trust Architecture. The updated versions of volumes A-D document three additional ZTA implementations that have been completed since the previous drafts were published. Volume E provides a risk analysis and mapping of ZTA security characteristics to cybersecurity standards and recommended practices. As the project progresses, the guide will be updated.
Access Control; Identification and Authentication; Risk Assessment; System and Communications Protection
Publication:
NIST SP 1800-35E iprd
Supplemental Material:
NIST SP 1800-35D 2prd (pdf)
NIST SP 1800-35C 2prd (pdf)
NIST SP 1800-35B 2prd (pdf)
NIST SP 1800-35A 2prd (pdf)
Project homepage (web)
Comment template (xls)
Document History:
08/09/22: SP 1800-35 (Draft)
12/21/22: SP 1800-35 (Draft)
Security and Privacy
access authorization; access control; authentication; security controls; zero trust
Technologies
firewalls; servers
Applications
communications & wireless; telework
Laws and Regulations
Executive Order 14028