Skip to main content
CPL

Compliance

48 controls

Govern security, compliance and data protection obligations to maintain defensible evidence of conformity with applicable internal and external requirements.

SCF # Control Name Weight NIST CSF Frameworks
CPL-01 Compliance Policy 10 — Critical Govern 1
CPL-02 Statutory, Regulatory & Contractual Compliance 10 — Critical Govern 158
CPL-03 Compliance Scope 10 — Critical Identify 40
CPL-04 Ability To Demonstrate Conformity 8 — High Protect 30
CPL-04.1 Conformity Assessment 9 — Critical Govern 27
CPL-04.2 Designated Certifying Official 5 — Medium Identify 2
CPL-04.3 Conformity Attestations 5 — Medium Identify 2
CPL-04.4 Declaration of Conformity 1 — Low Govern 11
CPL-05 Conformity Monitoring 10 — Critical Detect 87
CPL-05.1 Functional Review Of Security, Compliance & Resilience Controls 8 — High Detect 76
CPL-06 Non-Conformity Oversight 9 — Critical Respond 40
CPL-06.1 Non-Conformity Corrective Action 7 — High Govern 11
CPL-07 Executive Leadership Oversight of Security, Compliance & Resilience Controls 10 — Critical Detect 103
CPL-07.1 Internal Audit Function 5 — Medium Detect 42
CPL-07.2 Periodic Audits 8 — High Detect 26
CPL-07.3 Audit Planning Activities 5 — Medium Identify 13
CPL-08 Independent Assessors 6 — Medium Detect 51
CPL-09 Assessment Team Subject Matter Expertise 5 — Medium Protect 9
CPL-10 Assessor Access 7 — High Govern 6
CPL-11 Assessment Methods 7 — High Govern 1
CPL-12 Assessment Rigor 7 — High Govern 1
CPL-13 Assurance Levels (AL) 7 — High Govern 0
CPL-14 Control Reciprocity 5 — Medium Govern 1
CPL-15 Control Inheritance 5 — Medium Govern 0
CPL-16 Evidence Request List (ERL) 7 — High Govern 0
CPL-17 Evidence Sampling 7 — High Govern 0
CPL-18 Continuous Control Monitoring (CCM) 7 — High Govern 1
CPL-19 Legal Assessment of Investigative Inquires 2 — Low Respond 8
CPL-19.1 Investigation Request Notifications 2 — Low Respond 2
CPL-19.2 Investigation Access Restrictions 2 — Low Protect 11
CPL-20 Government Surveillance 10 — Critical Protect 4
CPL-21 Potential Human Rights Abuses 10 — Critical Protect 5
CPL-22 Grievances 5 — Medium Respond 9
CPL-22.1 Grievance Response 5 — Medium Respond 4
CPL-23 Localized Representation 2 — Low Govern 6
CPL-23.1 Representative Powers 2 — Low Govern 1
CPL-24 Dual Use Technology 8 — High Govern 0
CPL-24.1 USML or CCL Identification 8 — High Govern 0
CPL-24.2 Export-Controlled Access Restrictions 8 — High Govern 0
CPL-24.3 Export Activities Documentation 8 — High Govern 0
CPL-25 Statement of Applicability (SOA) 5 — Medium Protect 2
CPL-26 Work Products 8 — High Protect 4
CPL-26.1 Defensible Evidence of Due Diligence 8 — High Protect 2
CPL-26.2 Defensible Evidence of Due Care 8 — High Protect 2
CPL-27 Security, Compliance & Resilience Status Reporting 8 — High Govern 35
CPL-28 AI & Autonomous Technologies Registration 4 — Medium Protect 1
CPL-29 Control Assurance Automation (CAA) Oversight 7 — High Govern 0
CPL-30 Control Assurance Automation (CAA) Evidence Integrity & Provenance 8 — High Protect 1

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.