PRM
Project & Resource Management
15 controls
Operationalize security, compliance and resilience objectives by integrating cybersecurity and data privacy requirements into project, program and resource management practices.
| SCF # | Control Name | Weight |
|---|---|---|
| PRM-01 | Project & Resource Management Policy | 10 — Critical |
| PRM-02 | Strategic Plan & Objectives | 5 — Medium |
| PRM-03 | Targeted Capability Maturity Levels | 5 — Medium |
| PRM-04 | Security, Compliance & Resilience Protection Portfolio Management | 8 — High |
| PRM-04.1 | Purpose Validation | 5 — Medium |
| PRM-05 | Security, Compliance & Resilience Resource Management | 8 — High |
| PRM-05.1 | Commitment To Continual Improvements | 7 — High |
| PRM-05.2 | Prioritization To Address Evolving Risks & Threats | 5 — Medium |
| PRM-06 | Allocation of Resources | 8 — High |
| PRM-07 | Secure Development Life Cycle (SDLC) Management | 10 — Critical |
| PRM-08 | Security, Compliance & Resilience In Project Management | 10 — Critical |
| PRM-08.1 | Project Management Stage Gates | 7 — High |
| PRM-09 | Security, Compliance & Resilience Requirements Definition | 9 — Critical |
| PRM-10 | Business Process Definition | 7 — High |
| PRM-11 | Manage Organizational Knowledge | 5 — Medium |
The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.