Skip to main content
THR

Threat Management

17 controls

Proactively identify, assess and manage threats to Technology Assets, Applications, Services and Data (TAASD) and business processes to inform risk decisions and corrective actions.

SCF # Control Name Weight NIST CSF Frameworks
THR-01 Threat Management Policy 10 — Critical Govern 4
THR-02 Threat Intelligence Program 8 — High Govern 67
THR-03 Dynamic Threat Awareness 3 — Low Protect 5
THR-04 Threat Intelligence Feeds 8 — High Identify 96
THR-05 Threat Intelligence Reporting 8 — High Identify 21
THR-06 Threat Catalog 5 — Medium Protect 32
THR-07 Material Threats 7 — High Govern 5
THR-08 Threat Analysis 7 — High Protect 39
THR-09 Behavioral Baselining 5 — Medium Govern 9
THR-10 Predictive Cyber Analytics 3 — Low Protect 3
THR-11 Indicators of Exposure (IOE) 8 — High Identify 10
THR-12 Vulnerability Disclosure Program (VDP) 8 — High Detect 44
THR-12.1 Security Disclosure Contact Information 1 — Low Detect 3
THR-13 Threat Hunting 4 — Medium Detect 19
THR-14 Tainting 1 — Low Detect 9
THR-15 Insider Threat Program 8 — High Identify 24
THR-16 Insider Threat Awareness 8 — High Identify 35

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.