Engineering references

Standards guide the Atlas control model.

Atlas connects federal guidance and open identity standards to architecture, controls, implementation artifacts, interoperability profiles, and deployment evidence.

Federal architecture and assurance

Guidance mapped to system behavior.

These references shape terminology, decision boundaries, assurance selection, credential and federation controls, and evidence. Deployment evidence connects each control to its assessed operating environment.

ZT

NIST SP 800-207

Zero Trust Architecture informs resource-centered policy, continuous evaluation, separate policy decision and enforcement functions, and the absence of implicit trust from network location.

Official publication →
DI

NIST SP 800-63-4 suite

Digital Identity Guidelines inform risk-based selection of identity, authentication, and federation assurance; authenticator lifecycle; assertions; privacy; and relying-party acceptance.

Official guidelines →
PV

FIPS 201-3

Personal Identity Verification requirements inform federal credential, identity proofing, lifecycle, authentication, and interoperability patterns for employees and contractors.

Official standard →
AC

NIST SP 800-53

Security and privacy control families support control mapping across access control, identification and authentication, audit, configuration, continuity, and system integrity.

Official publication →
CN

NIST SP 800-207A

Cloud-native zero-trust guidance informs identity-tier policy, API gateways, service identity, and enforcement across hybrid and multi-cloud applications.

Official publication →
RM

NIST risk framing

Atlas separates technical evidence from the organization’s risk acceptance, system boundary, tailoring, assessment, authorization, and continuous monitoring processes.

Open identity standards

Protocols define the integration contract.

Atlas implements and qualifies profiles from open standards. Exact flow, algorithm, schema, claim, and operational choices remain part of the interoperability contract.

Standard familyAtlas usePrimary reference
OAuth 2.0 and extensionsDelegated API authorization, client policy, token exchange, proof of possession, device and backchannel profilesRFC 6749 and profile RFCs
OpenID ConnectFederated authentication, claims, discovery, UserInfo, relying-party and provider patternsOpenID Connect Core 1.0
SAMLEnterprise federation, metadata, assertions, bindings, signatures, encryption, and migrationOASIS SAML 2.0
SCIMCross-domain identity schema and lifecycle provisioningRFC 7643 and RFC 7644
WebAuthn and FIDOPublic-key, phishing-resistant authentication and authenticator lifecycleW3C WebAuthn
SPIFFEWorkload identity and mutually authenticated service integration patternsSPIFFE specifications
LDAPDirectory access, identity sources, group and attribute integrationRFC 4511

How standards are applied

From principle to control to evidence.

Atlas turns standards guidance into explicit implementation artifacts and verification, with organizational risk acceptance and authorization held by the responsible authority.

Reference

A requirement, recommendation, threat model, protocol clause, or architectural principle is selected.

Control and implementation

Atlas maps the reference to policy, configuration, service behavior, deployment dependency, and operator procedure.

Evidence and decision

Tests, receipts, configuration digests, operational proof, assessor review, and system authorization establish the actual claim.

Example: zero trust

Network location contributes context. Subject and device authentication remain distinct, resource policy evaluates the requested action, and sessions are re-evaluated as evidence changes.

Example: assurance

The relying party selects required IAL, AAL, and FAL through risk analysis. Atlas enforces eligible journeys and assertion policy and records the achieved assurance and dependencies.

Example: federation

Issuer, audience, signature, time, replay, subject, claim, and privacy checks are enforced for a specific protocol profile, with negative tests captured before routing.