Skip to main content
IAO

Information Assurance

17 controls

Execute Information Assurance (IA) practices to validate that expected security, compliance and resilience controls are appropriately designed and operating as intended for Technology Assets, Applications and Services (TAAS).

SCF # Control Name Weight NIST CSF Frameworks
IAO-01 Information Assurance Policy 10 — Critical Govern 1
IAO-02 Information Assurance (IA) Operations 10 — Critical Govern 86
IAO-03 Assessment Boundaries 9 — Critical Identify 31
IAO-04 Control Validation Testing (CVT) 10 — Critical Protect 96
IAO-04.1 Plan / Coordinate with Other Organizational Entities 5 — Medium Protect 33
IAO-05 Specialized Assessments 9 — Critical Protect 41
IAO-06 Assessor Independence 9 — Critical Protect 29
IAO-07 Third-Party Assessment Reciprocity 9 — Critical Protect 13
IAO-08 Adequate Security for Sensitive / Regulated Data In Support of Contracts 7 — High Protect 22
IAO-09 Applied Security, Compliance and Resilience Controls Documentation 7 — High Identify 69
IAO-10 Threat Analysis & Flaw Remediation During Development 10 — Critical Protect 35
IAO-11 Technical Verification 8 — High Protect 53
IAO-12 Capabilities Deficiency Tracking 9 — Critical Detect 80
IAO-12.1 Deficiency Tracking Automation 2 — Low Detect 4
IAO-13 Security Assessment Report (SAR) 7 — High Identify 17
IAO-14 Security Authorization 10 — Critical Protect 56
IAO-15 Control Assurance Automation (CAA) Automation 6 — Medium Protect 3

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.