# Assurance Infrastructure
**Entity class:** Security architecture
## Definition
**Assurance infrastructure** is the combined technical, administrative, and evidentiary machinery that makes a person, system, dataset, model, or action trustworthy enough for a defined use. It includes identity proofing, credentials, PKI, controls, authorization records, provenance, monitoring, audit, and revocation.
## Relationships
- **federal foundation:** [[wiki/Unified Federal Information Security Framework|Unified Federal Information Security Framework]].
- **machine-executable form:** [[wiki/Machine-Readable Assurance|Machine-Readable Assurance]].
- **lifecycle:** [[wiki/Risk Management Framework|Risk Management Framework]], [[wiki/Authorization to Operate|ATO]], and [[wiki/Continuous Monitoring|Continuous Monitoring]].
- **commercial comparator:** [[wiki/SOC 2 and the Trust Services Criteria|SOC 2 and the Trust Services Criteria]].
- **source:** [[research/Machine-Readable Assurance and the Convergence of Intelligence|Machine-Readable Assurance and the Convergence of Intelligence]].
## Sources / Provenance
- [NIST — SP 800-37 Rev. 2](https://csrc.nist.gov/pubs/sp/800/37/r2/final)
- [NIST — SP 800-53 Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)