Skip to main content
TDA

Technology Development & Acquisition

74 controls

Develop and acquire Technology Assets, Applications and Services (TAAS) through secure-by-design, risk-informed and resilient lifecycle practices.

SCF # Control Name Weight NIST CSF Frameworks
TDA-01 Technology Development & Acquisition Policy 10 — Critical Govern 32
TDA-02 Technology Development & Acquisition 10 — Critical Govern 95
TDA-03 Development Methods, Techniques & Processes 5 — Medium Identify 38
TDA-03.1 Software Assurance Maturity Model (SAMM) 9 — Critical Identify 21
TDA-03.2 Secure Settings By Default 9 — Critical Protect 13
TDA-04 Developer Architecture & Design 8 — High Protect 37
TDA-04.1 Programming Language Selection 7 — High Identify 1
TDA-05 Secure Software Development Practices (SSDP) 10 — Critical Protect 101
TDA-05.1 Criticality Analysis During Development 9 — Critical Protect 36
TDA-05.2 Threat Modeling 7 — High Identify 40
TDA-05.3 Supporting Toolchain 6 — Medium Identify 6
TDA-05.4 Software Design Review 10 — Critical Detect 16
TDA-05.5 Software Design Root Cause Analysis (RCA) 5 — Medium Protect 9
TDA-06 Product Management 10 — Critical Protect 54
TDA-06.1 Product Conformity Governance 9 — Critical Protect 3
TDA-06.2 Continuous Monitoring Plan 9 — Critical Detect 20
TDA-06.3 Ongoing Product Security Support 9 — Critical Protect 6
TDA-06.4 Integrity Mechanisms for Software / Firmware Updates 5 — Medium Protect 4
TDA-06.5 Software Release Integrity Verification 6 — Medium Protect 7
TDA-06.6 Information Assurance Enabled Products 2 — Low Protect 30
TDA-07 Disclosure of Vulnerabilities 5 — Medium Protect 8
TDA-07.1 Reporting Exploitable Vulnerabilities 8 — High Protect 1
TDA-08 Technical Documentation Artifacts 7 — High Protect 4
TDA-08.1 Product-Specific Risk Assessment Artifacts 4 — Medium Protect 1
TDA-08.2 Functional Properties 8 — High Protect 27
TDA-08.3 Administrator Documentation 8 — High Protect 46
TDA-08.4 Identification & Justification of Ports, Protocols & Services 8 — High Identify 27
TDA-08.5 Products With Digital Elements 6 — Medium Protect 1
TDA-09 Product Tampering and Counterfeiting (PTC) 9 — Critical Protect 32
TDA-10 Customized Development of Critical Components 8 — High Protect 14
TDA-11 DevSecOps 6 — Medium Protect 5
TDA-11.1 Minimum Viable Product (MVP) Security Requirements 9 — Critical Protect 64
TDA-11.2 Insecure Ports, Protocols & Services 9 — Critical Protect 14
TDA-11.3 Commercial Off-The-Shelf (COTS) Security Solutions 5 — Medium Protect 9
TDA-11.4 Logging Syntax 8 — High Detect 3
TDA-11.5 Physical Diagnostic & Test Interfaces 5 — Medium Detect 7
TDA-11.6 Diagnostic & Test Interface Monitoring 3 — Low Detect 2
TDA-12 Input Data Validation 9 — Critical Protect 48
TDA-12.1 Error Handling 9 — Critical Protect 25
TDA-12.2 Designated Roles To View Error Messages 6 — Medium Protect 2
TDA-13 Minimizing Attack Surfaces 9 — Critical Protect 3
TDA-13.1 Pre-Established Secure Configurations 8 — High Protect 18
TDA-13.2 Malware Testing Prior to Release 9 — Critical Protect 5
TDA-14 Product Testing & Reviews 9 — Critical Protect 7
TDA-14.1 Security, Compliance & Resilience Representatives For Product Changes 10 — Critical Identify 7
TDA-15 Secure Development Environments 9 — Critical Protect 36
TDA-15.1 Separation of Development, Testing and Operational Environments 10 — Critical Protect 51
TDA-15.2 Secure Migration Practices 8 — High Protect 13
TDA-16 Library Privileges 8 — High Protect 11
TDA-16.1 Access to Program Source Code 9 — Critical Protect 34
TDA-16.2 Approved Code 8 — High Protect 4
TDA-16.3 Archiving Software Releases 8 — High Protect 2
TDA-16.4 Software Escrow 7 — High Protect 8
TDA-17 Security, Compliance & Resilience Testing Throughout Development 9 — Critical Protect 82
TDA-17.1 Static Code Analysis 9 — Critical Detect 38
TDA-17.2 Dynamic Code Analysis 9 — Critical Detect 31
TDA-17.3 Malformed Input Testing 7 — High Detect 16
TDA-17.4 Application Penetration Testing 9 — Critical Detect 27
TDA-17.5 Manual Code Review 5 — Medium Detect 8
TDA-18 Use of Live Data 9 — Critical Protect 21
TDA-18.1 Test Data Integrity 8 — High Protect 2
TDA-19 Developer Screening 9 — Critical Protect 18
TDA-19.1 Developer Knowledge & Skills Register 7 — High Protect 1
TDA-19.2 Requisite Developer Training 7 — High Protect 4
TDA-20 Developer Configuration Management 9 — Critical Protect 32
TDA-20.1 Developer Threat Analysis & Flaw Remediation 9 — Critical Protect 35
TDA-20.2 Developer-Provided Training 9 — Critical Protect 15
TDA-20.3 Software / Firmware Integrity Verification 8 — High Protect 21
TDA-20.4 Hardware Integrity Verification 5 — Medium Protect 5
TDA-21 Bills of Material (BOMs) 9 — Critical Identify 4
TDA-21.1 Cryptographic Bill of Materials (CBOM) 7 — High Identify 3
TDA-21.2 Hardware Bill of Materials (HBOM) 9 — Critical Identify 3
TDA-21.3 Indentured Bill of Materials (IBOM) 9 — Critical Identify 0
TDA-21.4 Software Bill of Materials (SBOM) 9 — Critical Identify 29

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.