What KYD® Is NOT
What KYD® Is NOT
Section titled “What KYD® Is NOT”Version 1.0 — Non-Normative
Purpose
Section titled “Purpose”This document clarifies what KYD® does not define, does not claim, and does not replace.
Standards are defined as much by what they exclude as by what they include.
This document prevents misunderstanding and misuse.
What KYD® Does NOT Define
Section titled “What KYD® Does NOT Define”❌ KYD® is NOT a threat prevention system
Section titled “❌ KYD® is NOT a threat prevention system”What it is:
KYD® evaluates device trust based on observed behavior.
What it is NOT:
- A firewall
- An intrusion prevention system
- An endpoint protection platform
- A threat blocking mechanism
Why this matters:
Trust evaluation informs security decisions. It does not prevent threats directly.
❌ KYD® is NOT a security guarantee
Section titled “❌ KYD® is NOT a security guarantee”What it is:
KYD® provides evidence-based trust evaluation.
What it is NOT:
- A promise of security
- A guarantee against compromise
- A certification of safety
- A warranty of protection
Why this matters:
High trust indicates behavioral consistency. It does not guarantee invulnerability.
❌ KYD® is NOT a vulnerability scanner
Section titled “❌ KYD® is NOT a vulnerability scanner”What it is:
KYD® detects behavioral drift from established baselines.
What it is NOT:
- A CVE scanner
- A patch management tool
- A vulnerability assessment platform
- A penetration testing framework
Why this matters:
Vulnerability scanning identifies known weaknesses. KYD® evaluates trustworthiness based on behavior over time.
❌ KYD® is NOT an identity and access management (IAM) system
Section titled “❌ KYD® is NOT an identity and access management (IAM) system”What it is:
KYD® evaluates device identity and trust.
What it is NOT:
- User authentication
- Role-based access control (RBAC)
- Single sign-on (SSO)
- Privileged access management (PAM)
Why this matters:
KYD® focuses on devices, not users. IAM focuses on users, not devices. They are complementary, not substitutes.
❌ KYD® is NOT network access control (NAC)
Section titled “❌ KYD® is NOT network access control (NAC)”What it is:
KYD® evaluates device trust continuously.
What it is NOT:
- Port-based access control (802.1X)
- Network admission control
- Enforcement of network segmentation
- Connection blocking or quarantine
Why this matters:
NAC enforces network policy. KYD® provides trust data that NAC (or other systems) can use to inform enforcement decisions.
❌ KYD® is NOT a SIEM or log management platform
Section titled “❌ KYD® is NOT a SIEM or log management platform”What it is:
KYD® retains historical trust data and drift records.
What it is NOT:
- A general-purpose log aggregator
- A security information and event management (SIEM) platform
- A threat intelligence platform
- A log storage solution
Why this matters:
KYD® records trust-specific events. SIEM aggregates all security events. KYD® can send data to SIEM, but it is not a replacement.
❌ KYD® is NOT a compliance framework
Section titled “❌ KYD® is NOT a compliance framework”What it is:
KYD® can support compliance requirements related to device trust.
What it is NOT:
- ISO 27001
- SOC 2
- NIST Cybersecurity Framework
- PCI DSS
- HIPAA technical requirements
Why this matters:
KYD® provides device trust evidence that may satisfy portions of compliance frameworks. It does not replace comprehensive compliance programs.
❌ KYD® is NOT a specific product or vendor
Section titled “❌ KYD® is NOT a specific product or vendor”What it is:
KYD® is a standard. Multiple implementations may exist.
What it is NOT:
- KYD Verify (that’s the reference implementation)
- Any single vendor’s product
- A proprietary technology
- A locked ecosystem
Why this matters:
Standards are open. Products are implementations. Confusing the two kills credibility.
What KYD® Does NOT Claim
Section titled “What KYD® Does NOT Claim”❌ KYD® does NOT claim to prevent all attacks
Section titled “❌ KYD® does NOT claim to prevent all attacks”KYD® evaluates trust. Prevention requires additional controls.
❌ KYD® does NOT claim to detect all compromises
Section titled “❌ KYD® does NOT claim to detect all compromises”KYD® detects behavioral drift. Sophisticated adversaries may mimic expected behavior.
❌ KYD® does NOT claim to replace existing security tools
Section titled “❌ KYD® does NOT claim to replace existing security tools”KYD® complements firewalls, EDR, SIEM, IAM, and other security technologies.
❌ KYD® does NOT claim to be easy
Section titled “❌ KYD® does NOT claim to be easy”Continuous device trust evaluation requires observation, correlation, and analysis. Implementations vary in complexity.
❌ KYD® does NOT claim to be necessary for all environments
Section titled “❌ KYD® does NOT claim to be necessary for all environments”Some environments may not require continuous device trust evaluation. KYD® is designed for environments where device trust matters.
What KYD® Does NOT Replace
Section titled “What KYD® Does NOT Replace”❌ KYD® does NOT replace authentication
Section titled “❌ KYD® does NOT replace authentication”Devices must still authenticate to networks and systems.
❌ KYD® does NOT replace encryption
Section titled “❌ KYD® does NOT replace encryption”Data in transit and at rest must still be protected.
❌ KYD® does NOT replace vulnerability management
Section titled “❌ KYD® does NOT replace vulnerability management”Devices must still be patched and hardened.
❌ KYD® does NOT replace backup and recovery
Section titled “❌ KYD® does NOT replace backup and recovery”Data must still be backed up and recoverable.
❌ KYD® does NOT replace incident response
Section titled “❌ KYD® does NOT replace incident response”Organizations must still detect, respond to, and recover from incidents.
❌ KYD® does NOT replace security awareness training
Section titled “❌ KYD® does NOT replace security awareness training”Users must still be educated about threats and secure practices.
What KYD® Does NOT Require
Section titled “What KYD® Does NOT Require”❌ KYD® does NOT require specific hardware
Section titled “❌ KYD® does NOT require specific hardware”Software-only, hardware-anchored, and hybrid implementations are all valid.
❌ KYD® does NOT require agents on all devices
Section titled “❌ KYD® does NOT require agents on all devices”Observable network characteristics can establish identity and evaluate trust.
❌ KYD® does NOT require constant internet connectivity
Section titled “❌ KYD® does NOT require constant internet connectivity”Implementations may operate offline or in air-gapped environments.
❌ KYD® does NOT require cloud infrastructure
Section titled “❌ KYD® does NOT require cloud infrastructure”On-premise, cloud, edge, and hybrid deployments are all supported.
❌ KYD® does NOT require expensive infrastructure
Section titled “❌ KYD® does NOT require expensive infrastructure”Implementations scale to environment size and complexity.
Why This Matters
Section titled “Why This Matters”For Regulators:
Section titled “For Regulators:”KYD® has clear boundaries. It does not claim to solve all problems or replace all controls.
For Insurers:
Section titled “For Insurers:”KYD® provides specific, auditable evidence of device trust. It does not guarantee security outcomes.
For Enterprises:
Section titled “For Enterprises:”KYD® fits into existing security architectures. It does not require rip-and-replace.
For Implementers:
Section titled “For Implementers:”KYD® defines requirements, not implementation methods. Creativity and innovation are encouraged within the specification’s boundaries.
Summary
Section titled “Summary”KYD® is focused by design.
It does one thing:
Evaluates device trust continuously based on observed evidence.
It does not:
- Prevent threats
- Guarantee security
- Replace existing tools
- Claim to solve all problems
This focus is a feature, not a limitation.
Standards that try to do everything become meaningless.
Standards that do one thing well become foundational.
KYD® — The Device Trust Standard
Focused. Foundational. Verifiable.
Last Updated: January 2026
Authority: knowyourdevices.org