Skip to main content
END

Endpoint Security

31 controls

Harden and centrally manage endpoint devices to protect Technology Assets, Applications, Services and Data (TAASD) from unauthorized access, compromise and disruption.

SCF # Control Name Weight NIST CSF Frameworks
END-01 Endpoint Security Policy 10 — Critical Govern 1
END-02 Endpoint Device Management (EDM) 10 — Critical Govern 72
END-03 Endpoint Protection Mechanisms 9 — Critical Protect 68
END-03.1 Centralized Management of Endpoint Protection Mechanisms 8 — High Detect 24
END-03.2 Automatic Endpoint Protection Mechanism Updates 9 — Critical Protect 70
END-03.3 Evolving Endpoint Protection Threats 3 — Low Detect 6
END-03.4 Binary or Machine-Executable Code 5 — Medium Protect 6
END-04 Malicious Code Protection (Antimalware) 10 — Critical Detect 102
END-04.1 Always On Antimalware Protection 9 — Critical Detect 31
END-04.2 Heuristic / Nonsignature-Based Malware Detection 8 — High Detect 37
END-05 Antimalware Protection Mechanism Testing 5 — Medium Detect 4
END-06 Documented Endpoint Security Protection Measures 3 — Low Identify 5
END-07 Software Firewall 9 — Critical Protect 14
END-08 Unified Endpoint Device Management (UEDM) 6 — Medium Protect 4
END-09 Endpoint Detection & Response (EDR) 9 — Critical Respond 35
END-10 Extended Detection & Response (XDR) 5 — Medium Protect 6
END-11 Endpoint File Integrity Monitoring (FIM) 8 — High Protect 47
END-11.1 Endpoint Integrity Checks 6 — Medium Detect 28
END-11.2 Automated Notifications of Integrity Violations 5 — Medium Respond 9
END-11.3 Automated Response to Integrity Violations 5 — Medium Respond 9
END-11.4 Boot Process Integrity 5 — Medium Protect 6
END-11.5 Protection of Boot Firmware 5 — Medium Protect 11
END-12 Host Intrusion Detection and Prevention Systems (HIDS / HIPS) 9 — Critical Protect 15
END-13 Mobile Code 4 — Medium Detect 39
END-14 Collaborative Computing Devices 9 — Critical Protect 28
END-14.1 Collaborative Computing Capability Disabling / Removal In Secure Work Areas 5 — Medium Protect 6
END-14.2 Explicitly Indicate Current Participants 5 — Medium Protect 5
END-14.3 Participant Identity Verification 7 — High Protect 1
END-14.4 Participant Connection Management 5 — Medium Protect 1
END-14.5 Malicious Link & File Protections 7 — High Protect 2
END-14.6 Explicit Indication Of Use 6 — Medium Protect 5

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.