These links point to public material from government agencies, standards bodies and non-profit organisations. They are not owned by Kunan Technology; the publishing body is authoritative.
The baseline definition of zero trust, setting out how the policy engine, policy administrator and policy enforcement point divide responsibility. Almost every later architecture argument references it.
Extends the SP 800-207 principles into multi-cloud and service mesh environments, showing how identity and authorisation move down to the level of an individual service.
The specification for SDP itself, defining single packet authorisation and the separation of control and data planes — the architectural model Merak is built on.
The implementation-side companion to the specification, covering the trade-offs between deployment models — useful when matching an architecture to your own network constraints.
Breaks zero trust into five pillars — identity, devices, networks, applications and data — with maturity stages. A practical way to audit where you stand and decide what to adopt first.
The common language at governance level; version 2.0 adds a Govern function. Most international client security questionnaires are structured around it.
nist.gov
TaiwanLaws & Regulations Database, Ministry of Justice
Defines the security obligations of government agencies and designated non-government bodies in Taiwan; the legal basis for audit requirements on critical infrastructure providers.
law.moj.gov.tw
TaiwanLaws & Regulations Database, Ministry of Justice
The statutory framework for collecting, processing and transferring personal data, including cross-border transfer — the reference point for architecture decisions that move data offshore.