Skip to main content
WEB

Web Security

15 controls

Ensure the security and resilience of Internet-facing technologies through secure configuration management practices and monitoring for anomalous activity.

SCF # Control Name Weight NIST CSF Frameworks
WEB-01 Web Security 8 — High Govern 22
WEB-01.1 Unauthorized Code 9 — Critical Protect 5
WEB-02 Use of Demilitarized Zones (DMZ) 9 — Critical Protect 17
WEB-03 Web Application Firewall (WAF) 8 — High Protect 18
WEB-04 Client-Facing Web Services 10 — Critical Protect 10
WEB-05 Cookie Management 5 — Medium Identify 1
WEB-06 Strong Customer Authentication (SCA) 8 — High Protect 12
WEB-07 Web Security Standard 9 — Critical Protect 7
WEB-08 Web Application Framework 9 — Critical Protect 7
WEB-09 Validation & Sanitization 9 — Critical Protect 1
WEB-10 Secure Web Traffic 9 — Critical Protect 7
WEB-11 Output Encoding 9 — Critical Protect 1
WEB-12 Web Browser Security 9 — Critical Protect 2
WEB-13 Website Change Detection 8 — High Detect 5
WEB-14 Publicly Accessible Content Reviews 7 — High Identify 5

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.