SCF Control Reference
SCF 2026.31,591 controls across 34 domains mapped to 270+ frameworks
Security, Compliance & Resilience Governance
37 controlsGovern the organization’s Security, Compliance & Resilience Program (SCRP) through accountable oversight, evidence-based decision-making and defensible evidence that the organization is secure, compliant and resilient..
AATArtificial Intelligence & Autonomous Technologies
160 controlsGovern Artificial Intelligence & Autonomous Technologies (AAT) through trustworthy, secure and resilient lifecycle practices that manage intended and unintended outcomes..
ASTAsset Management
64 controlsManage Technology Assets, Applications and Services (TAAS) throughout their lifecycle to maintain visibility, accountability, authorization and protection..
BCDBusiness Continuity & Disaster Recovery
61 controlsMaintain resilient capabilities to sustain business-critical functions and recover from disruptions through documented, tested and maintained continuity and recovery processes..
CAPCapacity & Performance Planning
8 controlsGovern current and future capacity and performance requirements for Technology Assets, Applications, Services and Data (TAASD) to sustain reliable operations..
CHGChange Management
20 controlsManage changes to Technology Assets, Applications, Services and Data (TAASD) through an authorized, risk-based process that evaluates, implements and validates changes before and after deployment..
CLDCloud Security
19 controlsGovern cloud services and environments through risk-based, cloud-native security, compliance and resilience practices aligned with shared responsibility obligations..
CPLCompliance
48 controlsGovern security, compliance and data protection obligations to maintain defensible evidence of conformity with applicable internal and external requirements..
CFGConfiguration Management
58 controlsEstablish and enforce secure configuration baselines that implement least privilege and least functionality for Technology Assets, Applications and Services (TAAS) to support a defensible secure configuration posture..
MONContinuous Monitoring
76 controlsMaintain situational awareness through centralized collection, correlation and analysis of security-relevant telemetry from Technology Assets, Applications and Services (TAAS)..
CRYCryptographic Protections
27 controlsUse appropriate cryptographic mechanisms and industry-recognized key management practices to protect sensitive and regulated data at rest and in transit..
DCHData Classification & Handling
94 controlsEnforce a standardized classification methodology to determine data sensitivity and support Technology Assets, Applications and Services (TAAS) criticality decisions, enabling appropriate data handling, protection, retention and disposal requirements..
EMBEmbedded Technology
27 controlsApply risk-based security, compliance and resilience practices to embedded technologies where compromise or misuse could create operational, safety and/or data protection impacts..
ENDEndpoint Security
31 controlsHarden and centrally manage endpoint devices to protect Technology Assets, Applications, Services and Data (TAASD) from unauthorized access, compromise and disruption..
HRSHuman Resources Security
45 controlsExecute security-informed personnel management practices that address screening, onboarding, acceptable behavior, role-based risk, competence and offboarding requirements..
IACIdentification & Authentication
123 controlsImplement secure, compliant and resilient Identity and Access Management (IAM) capabilities that enforce least privilege across human users, devices, service accounts and other Non-Person Entities (NPEs)..
IROIncident Response
48 controlsMaintain a tested incident response capability that enables trained responders to identify, analyze, contain, eradicate and recover from incidents according to documented Incident Response Plans (IRPs)..
IAOInformation Assurance
17 controlsExecute Information Assurance (IA) practices to validate that expected security, compliance and resilience controls are appropriately designed and operating as intended for Technology Assets, Applications and Services (TAAS)..
MNTMaintenance
29 controlsProactively maintain Technology Assets, Applications and Services (TAAS) through authorized maintenance practices that preserve performance, security, compliance, resilience and supportability..
MDMMobile Device Management
10 controlsGovern mobile device access to Technology Assets, Applications, Services and Data (TAASD) to reduce attack surface and data exposure..
NETNetwork Security
103 controlsArchitect and implement defense-in-depth network protections that segment, restrict and monitor access to Technology Assets, Applications, Services and Data (TAASD)..
PESPhysical & Environmental Security
51 controlsProtect physical environments through layered physical security and environmental controls that safeguard physical and digital assets from unauthorized access, theft, damage and disruption..
PRIData Privacy
102 controlsExecute risk-based and legally defensible data privacy practices that conform with applicable statutory, regulatory and contractual obligations to protect sensitive Personal Data (sPD) throughout its lifecycle..
PRMProject & Resource Management
15 controlsOperationalize security, compliance and resilience objectives by integrating cybersecurity and data privacy requirements into project, program and resource management practices..
QTSQuantum Security
31 controlsMitigate quantum-enabled cryptographic risks through governance structures that operationalize Post-Quantum Cryptography (PQC) risk management practices..
RSKRisk Management
35 controlsProactively identify, assess, prioritize and treat risks to align Technology Assets, Applications, Services and Data (TAASD)-related decisions with the organization's defined risk appetite and risk tolerance..
SEASecure Engineering & Architecture
40 controlsApply industry-recognized secure engineering and architecture principles to deliver secure, compliant and resilient systems, applications and services..
OPSSecurity Operations
11 controlsDeliver secure, compliant and resilient operations through defined processes, skilled personnel, monitoring, escalation and continuous improvement that effectively detect, isolate, and remediate cyber threats while ensuring business resilience..
SATSecurity Awareness & Training
22 controlsFoster a security, compliance and resilience-minded workforce through ongoing, role-based education on evolving threats, obligations and secure workplace practices..
TDATechnology Development & Acquisition
74 controlsDevelop and acquire Technology Assets, Applications and Services (TAAS) through secure-by-design, risk-informed and resilient lifecycle practices..
TPMThird-Party Management
43 controlsExecute Supply Chain Risk Management (SCRM) practices to assess, select, contract, monitor and manage trustworthy third parties for product and service delivery..
THRThreat Management
17 controlsProactively identify, assess and manage threats to Technology Assets, Applications, Services and Data (TAASD) and business processes to inform risk decisions and corrective actions..
VPMVulnerability & Patch Management
32 controlsReduce exploitable weaknesses in Technology Assets, Applications and Services (TAAS) through coordinated vulnerability identification, prioritization, remediation and validation practices..
WEBWeb Security
13 controlsProtect Internet-facing Technology Assets, Applications and Services (TAAS) by minimizing attack surfaces and monitoring for anomalous activity..
The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.