Skip to main content
WEB

Web Security

13 controls

Protect Internet-facing Technology Assets, Applications and Services (TAAS) by minimizing attack surfaces and monitoring for anomalous activity.

SCF # Control Name Weight NIST CSF Frameworks
WEB-01 Web Security Policy 10 — Critical Govern 3
WEB-02 Web Security 8 — High Govern 19
WEB-03 Web Security Standard 9 — Critical Protect 7
WEB-04 Web Application Framework 9 — Critical Protect 6
WEB-05 Unauthorized Code On Web Pages 9 — Critical Protect 5
WEB-06 Client-Facing Web Services 10 — Critical Protect 10
WEB-07 Strong Customer Authentication (SCA) 8 — High Protect 13
WEB-08 Web Application Input Validation & Sanitization 9 — Critical Protect 2
WEB-09 Secure Web Traffic 9 — Critical Protect 10
WEB-10 Web Application Output Encoding 9 — Critical Protect 1
WEB-11 Web Browser Security 9 — Critical Protect 2
WEB-12 Website Change Detection 8 — High Detect 5
WEB-13 Publicly Accessible Content Reviews 7 — High Identify 7

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.