Skip to main content
SEA

Secure Engineering & Architecture

40 controls

Apply industry-recognized secure engineering and architecture principles to deliver secure, compliant and resilient systems, applications and services.

SCF # Control Name Weight NIST CSF Frameworks
SEA-01 Secure Engineering & Architecture Policy 10 — Critical Govern 2
SEA-02 Security, Compliance & Resilience Aware Design 7 — High Protect 15
SEA-02.1 Achieving Security, Compliance & Resilience Requirements 4 — Medium Protect 19
SEA-02.2 Flexible Technology Stack 5 — Medium Protect 1
SEA-03 Secure Architecture Principles 7 — High Protect 7
SEA-04 Alignment With Enterprise Architecture 9 — Critical Protect 73
SEA-05 Secure Engineering Principles 10 — Critical Govern 113
SEA-06 Defense-In-Depth (DiD) Architecture 10 — Critical Protect 62
SEA-07 System Partitioning 8 — High Protect 12
SEA-08 Application Partitioning 8 — High Protect 25
SEA-09 Process Isolation 7 — High Protect 31
SEA-10 Security Function Isolation 7 — High Protect 18
SEA-11 Hardware Separation 7 — High Protect 5
SEA-12 Thread Separation 7 — High Protect 5
SEA-13 System Privileges Isolation 5 — Medium Protect 1
SEA-14 Information In Shared Resources 8 — High Protect 35
SEA-15 Fail Secure 8 — High Protect 16
SEA-16 Fail Safe 8 — High Protect 11
SEA-17 Non-Persistence 9 — Critical Protect 10
SEA-17.1 Non-Persistent Information 7 — High Protect 3
SEA-18 Information Output Filtering 8 — High Protect 6
SEA-19 Memory Protection 8 — High Protect 25
SEA-20 Honeypots 3 — Low Protect 9
SEA-21 Honeyclients 3 — Low Protect 6
SEA-22 Heterogeneity 3 — Low Protect 13
SEA-23 Virtualization Techniques 6 — Medium Protect 15
SEA-23.1 Virtual Machine Images 8 — High Protect 3
SEA-24 Concealment & Misdirection 2 — Low Protect 12
SEA-24.1 Randomness 5 — Medium Protect 9
SEA-24.2 Change Processing & Storage Locations 5 — Medium Protect 10
SEA-25 Distributed Processing & Storage 4 — Medium Protect 11
SEA-26 Non-Modifiable Executable Programs 1 — Low Protect 7
SEA-27 Secure Log-On Procedures (Trusted Path) 8 — High Protect 10
SEA-28 System Use Notification (Logon Banner) 9 — Critical Protect 38
SEA-28.1 Standardized Microsoft Windows Banner 9 — Critical Protect 9
SEA-28.2 Truncated Banner 9 — Critical Protect 9
SEA-29 Previous Logon Notification 3 — Low Protect 5
SEA-30 Clock Synchronization 9 — Critical Protect 50
SEA-31 Application Container 5 — Medium Protect 3
SEA-32 Privileged Environments 5 — Medium Protect 2

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.