Skip to main content
GOV

Security, Compliance & Resilience Governance

37 controls

Govern the organization’s Security, Compliance & Resilience Program (SCRP) through accountable oversight, evidence-based decision-making and defensible evidence that the organization is secure, compliant and resilient.

SCF # Control Name Weight NIST CSF Frameworks
GOV-01 Security, Compliance & Resilience Governance Policy 10 — Critical Govern 13
GOV-02 Security, Compliance & Resilience Program (SCRP) 10 — Critical Govern 102
GOV-03 Centralized Management of Security, Compliance & Resilience Controls 9 — Critical Protect 28
GOV-03.1 Secure Practices Alignment Justification 8 — High Govern 13
GOV-03.2 Standardized Terminology 3 — Low Protect 33
GOV-03.3 Control Objectives 5 — Medium Govern 25
GOV-03.4 Assessment Objectives (AO) 7 — High Govern 1
GOV-04 Publishing Security, Compliance & Resilience Documentation 10 — Critical Govern 146
GOV-04.1 Periodic Review & Update of Security, Compliance & Resilience Program 7 — High Govern 101
GOV-04.2 Exception Management 8 — High Govern 17
GOV-04.3 Periodic Review of Exceptions 7 — High Govern 6
GOV-05 Assigned Security, Compliance & Resilience Responsibilities 10 — Critical Govern 105
GOV-05.1 Stakeholder Accountability Structure 8 — High Govern 55
GOV-05.2 Authoritative Chain of Command 7 — High Govern 31
GOV-06 Defining Business Context & Mission 5 — Medium Govern 27
GOV-07 Materiality Determination 7 — High Govern 8
GOV-08 High Value Assets (HVAs) 7 — High Govern 2
GOV-09 Steering Committee & Program Oversight 7 — High Govern 64
GOV-09.1 Status Reporting To Governing Body 5 — Medium Govern 53
GOV-10 Business As Usual (BAU) Security, Compliance & Resilience Practices 6 — Medium Govern 26
GOV-11 Operationalizing Security, Compliance & Resilience Capabilities 9 — Critical Govern 76
GOV-11.1 Select Controls 8 — High Govern 48
GOV-11.2 Implement Controls 9 — Critical Govern 44
GOV-11.3 Assess Controls 8 — High Govern 31
GOV-11.4 Authorize Technology Assets, Applications and/or Services (TAAS) 8 — High Govern 28
GOV-11.5 Monitor Controls 8 — High Govern 27
GOV-12 Measures of Performance 6 — Medium Govern 58
GOV-12.1 Key Performance Indicators (KPIs) 6 — Medium Govern 15
GOV-12.2 Key Risk Indicators (KRIs) 6 — Medium Govern 13
GOV-13 Forced Technology Transfer (FTT) 10 — Critical Govern 2
GOV-14 State-Sponsored Espionage 10 — Critical Govern 3
GOV-15 Contacts With Authorities 5 — Medium Govern 42
GOV-16 Contacts With Groups & Associations 7 — High Govern 31
GOV-17 Quality Management System (QMS) 4 — Medium Govern 4
GOV-18 Assurance 7 — High Govern 1
GOV-19 Mergers, Acquisitions & Divestitures (MA&D) 6 — Medium Govern 2
GOV-19.1 Virtual Data Room (VDR) 6 — Medium Govern 0

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.