Skip to main content
DCH

Data Classification & Handling

94 controls

Enforce a standardized classification methodology to determine data sensitivity and support Technology Assets, Applications and Services (TAAS) criticality decisions, enabling appropriate data handling, protection, retention and disposal requirements.

SCF # Control Name Weight NIST CSF Frameworks
DCH-01 Data Classification & Handling Policy 10 — Critical Govern 9
DCH-02 Data Protection 10 — Critical Govern 126
DCH-03 Sensitive / Regulated Data Governance 9 — Critical Govern 22
DCH-03.1 Data Catalog 7 — High Govern 3
DCH-04 Data & Asset Classification 10 — Critical Identify 81
DCH-04.1 Highest Classification Level 8 — High Protect 9
DCH-04.2 Data Reclassification 8 — High Protect 7
DCH-05 Sensitive Data Inventories 9 — Critical Detect 27
DCH-05.1 Periodic Scans for Sensitive / Regulated Data 7 — High Detect 9
DCH-06 Data Stewardship 10 — Critical Protect 35
DCH-06.1 Defining Access Authorizations for Sensitive / Regulated Data 9 — Critical Protect 34
DCH-07 Sensitive / Regulated Data Protection 9 — Critical Protect 69
DCH-07.1 Restrict Sensitive / Regulated Data Access To Authorized Individuals 8 — High Protect 48
DCH-08 Limitations on Use & Distribution of Sensitive / Regulated Data 10 — Critical Protect 8
DCH-08.1 Sensitive / Regulated Data Sharing Decisions 9 — Critical Protect 41
DCH-08.2 Disclosure of Sensitive / Regulated Data 10 — Critical Protect 34
DCH-08.3 Controlled Release of Sensitive / Regulated Data 4 — Medium Protect 9
DCH-08.4 Sensitive / Regulated Data Release Sanitization 8 — High Protect 2
DCH-09 Sensitive / Regulated Data Access Mapping 9 — Critical Identify 13
DCH-10 Sensitive / Regulated Media Records 6 — Medium Protect 7
DCH-11 Media Marking 7 — High Protect 37
DCH-11.1 Automated Marking 2 — Low Protect 21
DCH-12 Masking Displayed Sensitive / Regulated Data 7 — High Protect 15
DCH-12.1 Making Sensitive / Regulated Data Unreadable In Storage 9 — Critical Protect 8
DCH-13 Media Storage 8 — High Protect 52
DCH-13.1 Data Storage Location Reviews 8 — High Recover 5
DCH-14 Physically Secure All Media Containing Sensitive / Regulated Data 9 — Critical Protect 19
DCH-15 Storing Authentication Data 5 — Medium Protect 12
DCH-16 Media Transportation 9 — Critical Protect 54
DCH-16.1 Media Transportation Custodians 9 — Critical Protect 31
DCH-16.2 Encrypting Data Outside of Controlled Areas 5 — Medium Protect 36
DCH-17 Digital & Non-Digital Media Disposal 10 — Critical Protect 79
DCH-17.1 Dual Authorization for Sensitive / Regulated Data Destruction 5 — Medium Protect 5
DCH-18 Digital Media Sanitization 10 — Critical Protect 78
DCH-18.1 Sanitization of Sensitive / Regulated Data 9 — Critical Protect 38
DCH-18.2 Digital Media Sanitization Documentation 7 — High Protect 29
DCH-18.3 Digital Media Sanitization Equipment Testing 5 — Medium Detect 12
DCH-18.4 First Time Use Sanitization 5 — Medium Protect 9
DCH-19 Digital Media Use Restrictions 8 — High Protect 44
DCH-20 Portable Storage Devices 9 — Critical Protect 32
DCH-20.1 Prohibit Portable Storage Devices Use Without Owner 5 — Medium Protect 27
DCH-21 Removable Media Security 10 — Critical Protect 29
DCH-22 Use of External Technology Assets, Applications and/or Services (TAAS) 9 — Critical Protect 44
DCH-22.1 Limits of Authorized Use To Process, Store and/or Transmit Data 8 — High Protect 36
DCH-22.2 Protecting Sensitive / Regulated Data on External Technology Assets, Applications and/or Services (TAAS) 10 — Critical Protect 14
DCH-22.3 Non-Organizationally Owned Technology Assets, Applications and/or Services (TAAS) 5 — Medium Protect 13
DCH-23 Information Search & Retrieval 5 — Medium Protect 3
DCH-23.1 Electronic Discovery (eDiscovery) 8 — High Respond 2
DCH-24 Publicly Accessible Content 10 — Critical Protect 43
DCH-24.1 Data Mining Protection 7 — High Protect 10
DCH-25 Ad-Hoc Transfers 8 — High Protect 19
DCH-26 Transfer Authorizations 8 — High Protect 17
DCH-27 Media & Data Retention 8 — High Protect 94
DCH-27.1 Minimize Sensitive / Regulated Data Exposure 8 — High Protect 16
DCH-27.2 Archived Data Set Retention 8 — High Protect 1
DCH-27.3 Archiving Sensitive / Regulated Data 8 — High Protect 2
DCH-27.4 Mobile Device Data Retention Limitations 7 — High Protect 2
DCH-28 Limit Sensitive / Regulated Data In Testing, Training & Research 8 — High Protect 15
DCH-29 Logical Data Location 10 — Critical Identify 22
DCH-29.1 Automated Tools to Support Logical Data Location 6 — Medium Identify 14
DCH-30 Geographic Data Location 9 — Critical Identify 26
DCH-30.1 Geolocation Requirements for Processing, Storage and Service Locations 10 — Critical Protect 28
DCH-31 Data Localization 10 — Critical Protect 8
DCH-32 External Transfer of Sensitive / Regulated Data 10 — Critical Protect 14
DCH-33 Data Quality Operations 5 — Medium Protect 20
DCH-33.1 Data Management Board 3 — Low Identify 10
DCH-33.2 Data Quality Management 5 — Medium Identify 18
DCH-33.3 Data Quality Automation 1 — Low Identify 3
DCH-34 Data Modeling Guidelines 3 — Low Identify 4
DCH-34.1 Data Tags 3 — Low Protect 5
DCH-35 Data Analytics Bias 5 — Medium Identify 1
DCH-36 De-Identification (Anonymization) 8 — High Protect 42
DCH-36.1 Automated De-Identification of Sensitive / Regulated Data 1 — Low Protect 2
DCH-36.2 De-Identify Dataset Upon Collection 8 — High Protect 2
DCH-36.3 Removal, Masking, Encryption, Hashing or Replacement of Direct Identifiers 8 — High Protect 6
DCH-36.4 Statistical Disclosure Control 1 — Low Protect 2
DCH-36.5 Motivated Intruder 3 — Low Protect 3
DCH-36.6 Differential Privacy 1 — Low Protect 3
DCH-37 Cybersecurity & Data Protection Attributes 2 — Low Protect 7
DCH-37.1 Dynamic Attribute Association 2 — Low Protect 3
DCH-37.2 Attribute Value Changes By Authorized Individuals 8 — High Protect 2
DCH-37.3 Maintenance of Attribute Associations By System 2 — Low Protect 2
DCH-37.4 Association of Attributes By Authorized Individuals 2 — Low Protect 2
DCH-37.5 Attribute Displays for Output Devices 8 — High Protect 2
DCH-37.6 Data Subject Attribute Associations 2 — Low Protect 2
DCH-37.7 Consistent Attribute Interpretation 2 — Low Protect 2
DCH-37.8 Identity Association Techniques & Technologies 2 — Low Protect 2
DCH-37.9 Attribute Reassignment 7 — High Protect 3
DCH-37.10 Attribute Configuration By Authorized Individuals 8 — High Protect 2
DCH-37.11 Audit Changes 7 — High Detect 0
DCH-38 Code Names 1 — Low Protect 1
DCH-39 Data Rights Management (DRM) 6 — Medium Protect 3
DCH-40 Data Loss Prevention (DLP) 8 — High Protect 44
DCH-41 Control Assurance Automation (CAA) Aggregated Telemetry 6 — Medium Protect 0

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.