# Assurance Infrastructure **Entity class:** Security architecture ## Definition **Assurance infrastructure** is the combined technical, administrative, and evidentiary machinery that makes a person, system, dataset, model, or action trustworthy enough for a defined use. It includes identity proofing, credentials, PKI, controls, authorization records, provenance, monitoring, audit, and revocation. ## Relationships - **federal foundation:** [[wiki/Unified Federal Information Security Framework|Unified Federal Information Security Framework]]. - **machine-executable form:** [[wiki/Machine-Readable Assurance|Machine-Readable Assurance]]. - **lifecycle:** [[wiki/Risk Management Framework|Risk Management Framework]], [[wiki/Authorization to Operate|ATO]], and [[wiki/Continuous Monitoring|Continuous Monitoring]]. - **commercial comparator:** [[wiki/SOC 2 and the Trust Services Criteria|SOC 2 and the Trust Services Criteria]]. - **source:** [[research/Machine-Readable Assurance and the Convergence of Intelligence|Machine-Readable Assurance and the Convergence of Intelligence]]. ## Sources / Provenance - [NIST — SP 800-37 Rev. 2](https://csrc.nist.gov/pubs/sp/800/37/r2/final) - [NIST — SP 800-53 Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)