49% of NIST SP 800-207 you already have
API 1164 already covers about 49% of NIST SP 800-207, leaving
26 of 51 controls as genuinely new work.
Already covered 0
Likely covered 25
New work 26
No control in API 1164
maps directly to one in NIST SP 800-207. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in API 1164 reaches these. This is the list to scope.
SP800-207-2.1Tenet 1: All Data Sources and Computing Services as Resources
SP800-207-2.3Tenet 3: Per Session Resource Access
SP800-207-2.4Tenet 4: Dynamic Policy Driven Access
SP800-207-2.5Tenet 5: Monitor Integrity and Posture of Assets
SP800-207-2.6Tenet 6: Dynamic Authentication and Authorization
SP800-207-2.7Tenet 7: Telemetry to Improve Posture
SP800-207-3.1Policy Engine Capabilities
SP800-207-3.2Policy Administrator Role
SP800-207-3.3Policy Enforcement Point Coverage
SP800-207-3.4Continuous Diagnostics and Mitigation Inputs
SP800-207-3.5Identity Management Integration
SP800-207-4.1Enhanced Identity Governance Deployment
SP800-207-4.3Software Defined Perimeter Deployment
SP800-207-5.1Trust Algorithm Documentation
SP800-207-6.1ZTA Threats and Mitigations
SP800-207-7.1Migration Strategy and Roadmap
SP800-207-7.2Interoperability with Existing Controls
SP800-207-SC-CROSSENTDeployment Scenario: Collaboration Across Enterprise Boundaries
SP800-207-SUP-COMPLYIndustry Compliance System
SP800-207-SUP-IDMIdentity Management System
SP800-207-SUP-LOGSNetwork and System Activity Logs
SP800-207-SUP-SIEMSecurity Information and Event Management (SIEM) System
SP800-207-SUP-THREATThreat Intelligence Feeds
SP800-207-THR-DOSThreat: Denial-of-Service or Network Disruption
SP800-207-THR-PROPRIETARYThreat: Reliance on Proprietary Data Formats or Solutions
SP800-207-THR-SUBVERTThreat: Subversion of ZTA Decision Process
Show the 25 you already have
SP800-207-2.2Tenet 2: All Communication Secured Regardless of Network
SP800-207-4.2Micro Segmentation Deployment
SP800-207-DEP-AGENTDevice Agent/Gateway-Based Deployment
SP800-207-DEP-ENCLAVEEnclave-Based Deployment
SP800-207-DEP-PORTALResource Portal-Based Deployment
SP800-207-DEP-SANDBOXDevice Application Sandboxing
SP800-207-MIG-ACTORSMigration Step: Identify Actors on the Enterprise
SP800-207-MIG-ASSETSMigration Step: Identify Assets Owned by the Enterprise
SP800-207-MIG-DEPLOYMigration Step: Identify Candidate Solutions, Deploy, and Expand
SP800-207-MIG-POLICYMigration Step: Formulate Policies for the ZTA Candidate
SP800-207-MIG-PROCESSMigration Step: Identify Key Processes and Evaluate Risks
SP800-207-NET-REQNetwork Requirements to Support ZTA
SP800-207-SC-CONTRACTEDDeployment Scenario: Contracted Services and Nonemployee Access
SP800-207-SC-MULTICLOUDDeployment Scenario: Multi-cloud / Cloud-to-Cloud Enterprise
SP800-207-SC-PUBLICDeployment Scenario: Public- or Customer-Facing Services
SP800-207-SC-SATELLITEDeployment Scenario: Enterprise with Satellite Facilities
SP800-207-SUP-CDMContinuous Diagnostics and Mitigation (CDM) System
SP800-207-SUP-DAPData Access Policies
SP800-207-SUP-PKIEnterprise Public Key Infrastructure (PKI)
SP800-207-TA-CONTEXTSingular vs Contextual Trust Algorithm
SP800-207-TA-CRITERIACriteria-Based vs Score-Based Trust Algorithm
SP800-207-THR-CREDSThreat: Stolen Credentials and Insider Threat
SP800-207-THR-NPEThreat: Use of Non-Person Entities (NPE) in ZTA Administration
SP800-207-THR-STORAGEThreat: Storage of System and Network Information
SP800-207-THR-VISIBILITYThreat: Limited Visibility on the Network
How this is calculated
Already covered means a mapping runs from a control in API 1164 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition