THR
Threat Management
17 controls
Proactively identify, assess and manage threats to Technology Assets, Applications, Services and Data (TAASD) and business processes to inform risk decisions and corrective actions.
| SCF # | Control Name | Weight |
|---|---|---|
| THR-01 | Threat Management Policy | 10 — Critical |
| THR-02 | Threat Intelligence Program | 8 — High |
| THR-03 | Dynamic Threat Awareness | 3 — Low |
| THR-04 | Threat Intelligence Feeds | 8 — High |
| THR-05 | Threat Intelligence Reporting | 8 — High |
| THR-06 | Threat Catalog | 5 — Medium |
| THR-07 | Material Threats | 7 — High |
| THR-08 | Threat Analysis | 7 — High |
| THR-09 | Behavioral Baselining | 5 — Medium |
| THR-10 | Predictive Cyber Analytics | 3 — Low |
| THR-11 | Indicators of Exposure (IOE) | 8 — High |
| THR-12 | Vulnerability Disclosure Program (VDP) | 8 — High |
| THR-12.1 | Security Disclosure Contact Information | 1 — Low |
| THR-13 | Threat Hunting | 4 — Medium |
| THR-14 | Tainting | 1 — Low |
| THR-15 | Insider Threat Program | 8 — High |
| THR-16 | Insider Threat Awareness | 8 — High |
The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.