PEP · data plane
Untrusted admission. Enrolled workforce. WAN / on-the-wire. Admit, isolate, deny. Zero Trust →
Home · 800-207 mapping
NIST SP 800-207 · CISA Visibility and Analytics · not an ATO
House names map onto published terms. They do not replace them. Ikaros is the NIST SP 800-207 policy engine (PE). AEGIS is the policy administrator (PA). Together they are the policy decision point (PDP). Edge PEPs are policy enforcement points on the data plane. CDM-class telemetry, identity, network, crypto-health, and ATT&CK evidence are data sources into the engine — CISA Visibility and Analytics — not sister products. Mapping is not an ATO.
PE and PA command PEPs on the control plane. Subject-to-resource traffic is the data plane. When data sources arrive, that is instrumentation. When Ikaros decides, that is the policy engine under human sovereignty — not unconstrained autonomy. Dual-plane admission is two PEP classes: untrusted is never enrolled. Content policy is enrolled-path only. This origin is not a PEP.
Untrusted admission. Enrolled workforce. WAN / on-the-wire. Admit, isolate, deny. Zero Trust →
800-207 feeds. CISA Visibility and Analytics. QFC fuses one schema. Silos do not rank. Fusion →
PE. Trust algorithm is CEP-Rank. Ingest, fuse, rank, propose. Ikaros →
PA. HUMAN_ONLY gate. Commands the PEP on the control plane. Guide on this origin is the same name, different job.
The enrolled content path is the technical child of enterprise secure web gateways (Bluecoat-class, open source). It does not intercept the entire Internet for every device. On the private, enrolled PEP, policy may terminate TLS under an enterprise inspection CA, inspect (category, ICAP, malware), then re-encrypt to origin—or pass through, or deny.
Untrusted-plane traffic is not default-inspected; public CAs after grant when internet is allowed. That split is deliberate: reliability on the untrusted path; depth of control where trust is earned.