Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST CSWP 20 (Initial Public Draft)

Planning for a Zero Trust Architecture: A Starting Guide for Administrators

Date Published: August 4, 2021
Comments Due: September 3, 2021 (public comment period is CLOSED)
Email Questions to: zerotrust-arch@nist.gov

Author(s)

Scott Rose (NIST)

Announcement

This draft white paper provides a high-level overview of the NIST Risk Management Framework (NIST RMF) and how it can help in developing and implementing a zero trust architecture.

Zero trust is a set of cybersecurity principles used by stakeholders to plan and implement an enterprise architecture. Since some of these stakeholders may not be familiar with risk analysis and management, the NIST RMF provides a common set of concepts and tasks to both security planners and system operators.

Abstract

Keywords

architecture; information technology; risk; zero trust
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.CSWP.20.ipd
Download URL

Supplemental Material:
Local Download (pdf)

Document History:
08/04/21: CSWP 20 (Draft)
05/06/22: CSWP 20 (Final)

Topics

Security and Privacy

planning, risk management, zero trust

Technologies

networks

Applications

enterprise