IAO
Information Assurance
17 controls
Execute Information Assurance (IA) practices to validate that expected security, compliance and resilience controls are appropriately designed and operating as intended for Technology Assets, Applications and Services (TAAS).
| SCF # | Control Name | Weight |
|---|---|---|
| IAO-01 | Information Assurance Policy | 10 — Critical |
| IAO-02 | Information Assurance (IA) Operations | 10 — Critical |
| IAO-03 | Assessment Boundaries | 9 — Critical |
| IAO-04 | Control Validation Testing (CVT) | 10 — Critical |
| IAO-04.1 | Plan / Coordinate with Other Organizational Entities | 5 — Medium |
| IAO-05 | Specialized Assessments | 9 — Critical |
| IAO-06 | Assessor Independence | 9 — Critical |
| IAO-07 | Third-Party Assessment Reciprocity | 9 — Critical |
| IAO-08 | Adequate Security for Sensitive / Regulated Data In Support of Contracts | 7 — High |
| IAO-09 | Applied Security, Compliance and Resilience Controls Documentation | 7 — High |
| IAO-10 | Threat Analysis & Flaw Remediation During Development | 10 — Critical |
| IAO-11 | Technical Verification | 8 — High |
| IAO-12 | Capabilities Deficiency Tracking | 9 — Critical |
| IAO-12.1 | Deficiency Tracking Automation | 2 — Low |
| IAO-13 | Security Assessment Report (SAR) | 7 — High |
| IAO-14 | Security Authorization | 10 — Critical |
| IAO-15 | Control Assurance Automation (CAA) Automation | 6 — Medium |
The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.