SCF Domains & Principles

The SCF organizes 1,400+ controls into 33 logically structured domains, covering every aspect of cybersecurity and data privacy in a single, unified taxonomy. Each domain contains numbered principles so that GOV-03 means the same thing to every organization using the SCF, worldwide.

33 Domains
1,400+ Controls
200+ Frameworks Mapped
FREE Creative Commons

SCF Domains Overview

All 33 SCF Domains

Search by name, code, or keyword. Filter by category. Click any card to expand its full description, related keywords, and example controls.

All 33
Governance & Management
Technical Controls
Security Operations
Data & Privacy
People & Physical

GOVERNANCE](GOV)

Security, Compliance & Resilience Governance

Execute a documented, risk-based program that supports business objectives while encompassing appropriate cybersecurity & data protection principles that addresses applicable statutory, regulatory and contractual obligations.

AAT

Artificial Intelligence and Autonomous Technology

Ensure trustworthy and resilient Artificial Intelligence (AI) and autonomous technologies to achieve a beneficial impact by informing, advising or simplifying tasks, while minimizing emergent properties or unintended consequences.

AST

Asset Management

Manage all technology assets from purchase through disposition, both physical and virtual, to ensure secured use, regardless of the asset's location.

BCD

Business Continuity & Disaster Recovery

Maintain a resilient capability to sustain business-critical functions while successfully responding to and recovering from incidents through well-documented and exercised processes.

CAP

Capacity & Performance Planning

Govern the current and future capacities and performance of technology assets.

CHG

Change Management

Manage change in a sustainable and ongoing manner that involves active participation from both technology and business stakeholders to ensure that only authorized changes occur.

CLD

Cloud Security

Govern cloud instances as an extension of on-premise technologies with equal or greater security protections than the organization's own internal cybersecurity & data privacy controls.

CPL

Compliance

Oversee the execution of cybersecurity & data privacy controls to ensure appropriate evidence required due care and due diligence exists to meet compliance with applicable statutory, regulatory and contractual obligations.

CFG

Configuration Management

Enforce secure configurations according to vendor-recommended and industry-recognized secure practices that enforce the concepts of 'least privilege' and 'least functionality' for all systems, applications and services.

MON

Continuous Monitoring

Maintain situational awareness of security-related events through the centralized collection and analysis of event logs from systems, applications and services.

CRY

Cryptographic Protections

Utilize appropriate cryptographic solutions and industry-recognized key management practices to protect the confidentiality and integrity of sensitive/regulated data both at rest and in transit.

DCH

Data Classification & Handling

Enforce a standardized data classification methodology to objectively determine the sensitivity and criticality of all data and technology assets so that proper handling and disposal requirements can be followed.

EMB

Embedded Technology

Provide additional scrutiny to reduce the risks associated with embedded technology, based on the potential damages posed from malicious use of the technology.

END

Endpoint Security

Harden endpoint devices to protect against reasonable threats to those devices and the data those devices store, transmit and process.

HRS

Human Resources Security

Execute sound hiring practices and ongoing personnel management to cultivate a cybersecurity & data privacy-minded workforce.

IAC

Identification & Authentication

Enforce the concept of "least privilege" consistently across all systems, applications and services for individual, group and service accounts through a documented and standardized Identity and Access Management (IAM) capability.

IRO

Incident Response

Maintain a viable incident response capability that trains personnel on how to recognize and report suspicious activities so that trained incident responders can take the appropriate steps to handle incidents, in accordance with a documented Incident Response Plan (IRP).

IAO

Information Assurance

Execute an impartial assessment process to validate the existence and functionality of appropriate cybersecurity & data privacy controls, prior to a system, application or service being used in a production environment.

MNT

Maintenance

Proactively maintain technology assets, according to current vendor recommendations for configurations and updates, including those supported or hosted by third-parties.

MDM

Mobile Device Management

Implement measures to restrict mobile device connectivity with critical infrastructure and sensitive/regulated data that limit the attack surface and potential data exposure from mobile device usage.

NET

Network Security

Architect and implement a secure and resilient defense-in-depth methodology that enforces the concept of 'least functionality' through restricting network access to systems, applications and services.

PES

Physical & Environmental Security

Protect physical environments through layers of physical security and environmental controls that work together to protect both physical and digital assets from theft and damage.

PRI

Data Privacy

Align data privacy practices with industry-recognized data privacy principles to implement appropriate administrative, technical and physical controls to protect regulated personal data throughout the lifecycle of systems, applications and services.

PRM

Project & Resource Management

Operationalize a viable strategy to achieve cybersecurity & data privacy objectives that establishes cybersecurity as a key stakeholder within project management practices to ensure the delivery of resilient and secure solutions.

RSK

Risk Management

Proactively identify, assess, prioritize and remediate risk through alignment with industry-recognized risk management principles to ensure risk decisions adhere to the organization's risk threshold.

SEA

Secure Engineering & Architecture

Utilize industry-recognized secure engineering and architecture principles to deliver secure and resilient systems, applications and services.

OPS

Security Operations

Execute the delivery of cybersecurity & data privacy operations to provide quality services and secure systems, applications and services that meet the organization's business needs.

SAT

Security Awareness & Training

Foster a cybersecurity & data privacy-minded workforce through ongoing user education about evolving threats, compliance obligations and secure workplace practices.

TDA

Technology Development & Acquisition

Develop and/or acquire systems, applications and services according to a Secure Software Development Framework (SSDF) to reduce the potential impact of undetected or unaddressed vulnerabilities and design flaws.

TPM

Third-Party Management

Execute Supply Chain Risk Management (SCRM) practices so that only trustworthy third-parties are used for products and/or service delivery.

THR

Threat Management

Proactively identify and assess technology-related threats, to both assets and business processes, to determine the applicable risk and necessary corrective action.

VPM

Vulnerability & Patch Management

Leverage industry-recognized Attack Surface Management (ASM) practices to strengthen the security and resilience of systems, applications and services against evolving and sophisticated attack vectors.

WEB

Web Security

Ensure the security and resilience of Internet-facing technologies through secure configuration management practices and monitoring for anomalous activity.

Universal Control Taxonomy

One Language for Every Organization

The SCF's naming convention is a core feature of the Common Controls Framework™. Every control is identified by a three-letter domain code plus a sequential number, enabling universal, inter-organizational control language that removes ambiguity. Domain codes and control numbers are stable even as controls are updated, making version management across GRC tools reliable.

Inter-organizational standardization
Inter-organizational standardization: GOV-03 means the same thing to your organization as it does to any other SCF user, whether a vendor, assessor, regulator, or partner. That shared language is uniquely valuable.

Universal Control Taxonomy

  • Domain Code: GOV
  • Control Number: 03
  • 3-Letter Domain Code: Identifies the control domain
  • Numeric Sequence: Unique within domain
  • Global Universal: Same meaning everywhere

Controls Overview

Controls are your security, compliance & resilience program - A control is the power to influence or direct behaviors and the course of events.

%20(white).png)