NIST SP 800-207
Zero Trust Architecture informs resource-centered policy, continuous evaluation, separate policy decision and enforcement functions, and the absence of implicit trust from network location.
Official publication →Engineering references
Atlas connects federal guidance and open identity standards to architecture, controls, implementation artifacts, interoperability profiles, and deployment evidence.
Federal architecture and assurance
These references shape terminology, decision boundaries, assurance selection, credential and federation controls, and evidence. Deployment evidence connects each control to its assessed operating environment.
Zero Trust Architecture informs resource-centered policy, continuous evaluation, separate policy decision and enforcement functions, and the absence of implicit trust from network location.
Official publication →Digital Identity Guidelines inform risk-based selection of identity, authentication, and federation assurance; authenticator lifecycle; assertions; privacy; and relying-party acceptance.
Official guidelines →Personal Identity Verification requirements inform federal credential, identity proofing, lifecycle, authentication, and interoperability patterns for employees and contractors.
Official standard →Security and privacy control families support control mapping across access control, identification and authentication, audit, configuration, continuity, and system integrity.
Official publication →Cloud-native zero-trust guidance informs identity-tier policy, API gateways, service identity, and enforcement across hybrid and multi-cloud applications.
Official publication →Atlas separates technical evidence from the organization’s risk acceptance, system boundary, tailoring, assessment, authorization, and continuous monitoring processes.
Open identity standards
Atlas implements and qualifies profiles from open standards. Exact flow, algorithm, schema, claim, and operational choices remain part of the interoperability contract.
| Standard family | Atlas use | Primary reference |
|---|---|---|
| OAuth 2.0 and extensions | Delegated API authorization, client policy, token exchange, proof of possession, device and backchannel profiles | RFC 6749 and profile RFCs |
| OpenID Connect | Federated authentication, claims, discovery, UserInfo, relying-party and provider patterns | OpenID Connect Core 1.0 |
| SAML | Enterprise federation, metadata, assertions, bindings, signatures, encryption, and migration | OASIS SAML 2.0 |
| SCIM | Cross-domain identity schema and lifecycle provisioning | RFC 7643 and RFC 7644 |
| WebAuthn and FIDO | Public-key, phishing-resistant authentication and authenticator lifecycle | W3C WebAuthn |
| SPIFFE | Workload identity and mutually authenticated service integration patterns | SPIFFE specifications |
| LDAP | Directory access, identity sources, group and attribute integration | RFC 4511 |
How standards are applied
Atlas turns standards guidance into explicit implementation artifacts and verification, with organizational risk acceptance and authorization held by the responsible authority.
A requirement, recommendation, threat model, protocol clause, or architectural principle is selected.
Atlas maps the reference to policy, configuration, service behavior, deployment dependency, and operator procedure.
Tests, receipts, configuration digests, operational proof, assessor review, and system authorization establish the actual claim.
Network location contributes context. Subject and device authentication remain distinct, resource policy evaluates the requested action, and sessions are re-evaluated as evidence changes.
The relying party selects required IAL, AAL, and FAL through risk analysis. Atlas enforces eligible journeys and assertion policy and records the achieved assurance and dependencies.
Issuer, audience, signature, time, replay, subject, claim, and privacy checks are enforced for a specific protocol profile, with negative tests captured before routing.