Skip to main content

SCF Control Reference

SCF 2026.3

1,591 controls across 34 domains mapped to 270+ frameworks

GOV

Security, Compliance & Resilience Governance

37 controls

Govern the organization’s Security, Compliance & Resilience Program (SCRP) through accountable oversight, evidence-based decision-making and defensible evidence that the organization is secure, compliant and resilient..

AAT

Artificial Intelligence & Autonomous Technologies

160 controls

Govern Artificial Intelligence & Autonomous Technologies (AAT) through trustworthy, secure and resilient lifecycle practices that manage intended and unintended outcomes..

AST

Asset Management

64 controls

Manage Technology Assets, Applications and Services (TAAS) throughout their lifecycle to maintain visibility, accountability, authorization and protection..

BCD

Business Continuity & Disaster Recovery

61 controls

Maintain resilient capabilities to sustain business-critical functions and recover from disruptions through documented, tested and maintained continuity and recovery processes..

CAP

Capacity & Performance Planning

8 controls

Govern current and future capacity and performance requirements for Technology Assets, Applications, Services and Data (TAASD) to sustain reliable operations..

CHG

Change Management

20 controls

Manage changes to Technology Assets, Applications, Services and Data (TAASD) through an authorized, risk-based process that evaluates, implements and validates changes before and after deployment..

CLD

Cloud Security

19 controls

Govern cloud services and environments through risk-based, cloud-native security, compliance and resilience practices aligned with shared responsibility obligations..

CPL

Compliance

48 controls

Govern security, compliance and data protection obligations to maintain defensible evidence of conformity with applicable internal and external requirements..

CFG

Configuration Management

58 controls

Establish and enforce secure configuration baselines that implement least privilege and least functionality for Technology Assets, Applications and Services (TAAS) to support a defensible secure configuration posture..

MON

Continuous Monitoring

76 controls

Maintain situational awareness through centralized collection, correlation and analysis of security-relevant telemetry from Technology Assets, Applications and Services (TAAS)..

CRY

Cryptographic Protections

27 controls

Use appropriate cryptographic mechanisms and industry-recognized key management practices to protect sensitive and regulated data at rest and in transit..

DCH

Data Classification & Handling

94 controls

Enforce a standardized classification methodology to determine data sensitivity and support Technology Assets, Applications and Services (TAAS) criticality decisions, enabling appropriate data handling, protection, retention and disposal requirements..

EMB

Embedded Technology

27 controls

Apply risk-based security, compliance and resilience practices to embedded technologies where compromise or misuse could create operational, safety and/or data protection impacts..

END

Endpoint Security

31 controls

Harden and centrally manage endpoint devices to protect Technology Assets, Applications, Services and Data (TAASD) from unauthorized access, compromise and disruption..

HRS

Human Resources Security

45 controls

Execute security-informed personnel management practices that address screening, onboarding, acceptable behavior, role-based risk, competence and offboarding requirements..

IAC

Identification & Authentication

123 controls

Implement secure, compliant and resilient Identity and Access Management (IAM) capabilities that enforce least privilege across human users, devices, service accounts and other Non-Person Entities (NPEs)..

IRO

Incident Response

48 controls

Maintain a tested incident response capability that enables trained responders to identify, analyze, contain, eradicate and recover from incidents according to documented Incident Response Plans (IRPs)..

IAO

Information Assurance

17 controls

Execute Information Assurance (IA) practices to validate that expected security, compliance and resilience controls are appropriately designed and operating as intended for Technology Assets, Applications and Services (TAAS)..

MNT

Maintenance

29 controls

Proactively maintain Technology Assets, Applications and Services (TAAS) through authorized maintenance practices that preserve performance, security, compliance, resilience and supportability..

MDM

Mobile Device Management

10 controls

Govern mobile device access to Technology Assets, Applications, Services and Data (TAASD) to reduce attack surface and data exposure..

NET

Network Security

103 controls

Architect and implement defense-in-depth network protections that segment, restrict and monitor access to Technology Assets, Applications, Services and Data (TAASD)..

PES

Physical & Environmental Security

51 controls

Protect physical environments through layered physical security and environmental controls that safeguard physical and digital assets from unauthorized access, theft, damage and disruption..

PRI

Data Privacy

102 controls

Execute risk-based and legally defensible data privacy practices that conform with applicable statutory, regulatory and contractual obligations to protect sensitive Personal Data (sPD) throughout its lifecycle..

PRM

Project & Resource Management

15 controls

Operationalize security, compliance and resilience objectives by integrating cybersecurity and data privacy requirements into project, program and resource management practices..

QTS

Quantum Security

31 controls

Mitigate quantum-enabled cryptographic risks through governance structures that operationalize Post-Quantum Cryptography (PQC) risk management practices..

RSK

Risk Management

35 controls

Proactively identify, assess, prioritize and treat risks to align Technology Assets, Applications, Services and Data (TAASD)-related decisions with the organization's defined risk appetite and risk tolerance..

SEA

Secure Engineering & Architecture

40 controls

Apply industry-recognized secure engineering and architecture principles to deliver secure, compliant and resilient systems, applications and services..

OPS

Security Operations

11 controls

Deliver secure, compliant and resilient operations through defined processes, skilled personnel, monitoring, escalation and continuous improvement that effectively detect, isolate, and remediate cyber threats while ensuring business resilience..

SAT

Security Awareness & Training

22 controls

Foster a security, compliance and resilience-minded workforce through ongoing, role-based education on evolving threats, obligations and secure workplace practices..

TDA

Technology Development & Acquisition

74 controls

Develop and acquire Technology Assets, Applications and Services (TAAS) through secure-by-design, risk-informed and resilient lifecycle practices..

TPM

Third-Party Management

43 controls

Execute Supply Chain Risk Management (SCRM) practices to assess, select, contract, monitor and manage trustworthy third parties for product and service delivery..

THR

Threat Management

17 controls

Proactively identify, assess and manage threats to Technology Assets, Applications, Services and Data (TAASD) and business processes to inform risk decisions and corrective actions..

VPM

Vulnerability & Patch Management

32 controls

Reduce exploitable weaknesses in Technology Assets, Applications and Services (TAAS) through coordinated vulnerability identification, prioritization, remediation and validation practices..

WEB

Web Security

13 controls

Protect Internet-facing Technology Assets, Applications and Services (TAAS) by minimizing attack surfaces and monitoring for anomalous activity..

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.