Framework overlap

Does NIST SP 800-207 cover DoD Zero Trust Reference Architecture?

You hold NIST SP 800-207 and have been told to do DoD Zero Trust Reference Architecture. Here is how much overlaps, control by control.

38% of DoD Zero Trust Reference Architecture you already have

NIST SP 800-207 already covers about 38% of DoD Zero Trust Reference Architecture, leaving 28 of 45 controls as genuinely new work.

Already covered 4 Likely covered 13 New work 28

What is genuinely new work

Nothing in NIST SP 800-207 reaches these. This is the list to scope.

DODZT-1.2
Conditional User Access
DODZT-1.5
Identity Federation and User Credentialing
DODZT-1.6
Behavioral, Contextual ID, and Biometrics
DODZT-1.9
Integrated ICAM Platform
DODZT-2.2
Device Detection and Compliance
DODZT-2.3
Device Authorization with Real-Time Inspection
DODZT-2.4
Remote Access
DODZT-2.5
Partially and Fully Automated Asset, Vulnerability and Patch Management
DODZT-2.6
Unified Endpoint Management and Mobile Device Management
DODZT-3.2
Secure Software Development and Integration
DODZT-3.3
Software Risk Management
DODZT-3.4
Resource Authorization and Integration
DODZT-4.1
Data Catalog Risk Alignment
DODZT-4.2
DoD Enterprise Data Governance
DODZT-4.3
Data Labeling and Tagging
DODZT-4.4
Data Monitoring and Sensing
DODZT-4.5
Data Encryption and Rights Management
DODZT-4.6
Data Loss Prevention
DODZT-5.2
Software Defined Networking
DODZT-6.2
Critical Process Automation
DODZT-6.3
Machine Learning
DODZT-6.4
Artificial Intelligence
DODZT-6.5
Security Orchestration, Automation and Response
DODZT-6.6
API Standardization
DODZT-6.7
Security Operations Center and Incident Response
DODZT-7.1
Log All Traffic
DODZT-7.2
Security Information and Event Management
DODZT-7.3
Common Security and Risk Analytics
Show the 17 you already have
DODZT-1.8
Continuous Authentication
DODZT-4.7
Data Access Control
DODZT-6.1
Policy Decision Point and Policy Orchestration
DODZT-7.6
Automated Dynamic Policies
DODZT-1.1
User Inventory
DODZT-1.3
Multi-Factor Authentication
DODZT-1.4
Privileged Access Management
DODZT-1.7
Least Privileged Access
DODZT-2.1
Device Inventory
DODZT-2.7
Endpoint and Extended Detection and Response
DODZT-3.1
Application Inventory
DODZT-3.5
Continuous Monitoring and Ongoing Authorizations
DODZT-5.1
Data Flow Mapping
DODZT-5.3
Macro Segmentation
DODZT-5.4
Micro Segmentation
DODZT-7.4
User and Entity Behavior Analytics
DODZT-7.5
Threat Intelligence Integration

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-207 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition