Policy Engine (PE)

The NIST SP 800-207 zero trust component that makes the final grant, deny or revoke decision on a subject's access to a resource, feeding policy and live signals into a trust algorithm.

The policy engine is the decision-making component of zero trust architecture in NIST SP 800-207. It is responsible for the final decision to grant a subject access to a resource. It takes enterprise policy together with inputs from other sources, such as continuous diagnostics data on device state, threat intelligence, activity logs and identity management, and uses them in a trust algorithm to grant, deny or revoke access. It logs each decision and hands execution to the policy administrator, which instructs the policy enforcement point.

Together, the engine and the administrator make up the policy decision point in the SP 800-207 model. The engine is where the continuous verification of zero trust takes place: because it can revoke as well as grant, a change in device posture or risk during a session can end access that was approved at the start. This ties it closely to risk-based access control. The data sources that feed it play the part a policy information point plays in attribute-based designs.

Exam relevance: a scenario is likely to describe a zero trust deployment and ask which component decides whether access is allowed. Candidates are expected to name the policy engine, to know that SP 800-207 pairs it with the policy administrator, and to treat that pair as the PDP.