SCF Domains & Principles
The SCF organizes 1,400+ controls into 33 logically structured domains, covering every aspect of cybersecurity and data privacy in a single, unified taxonomy. Each domain contains numbered principles so that GOV-03 means the same thing to every organization using the SCF, worldwide.
33 Domains
1,400+ Controls
200+ Frameworks Mapped
FREE Creative Commons
SCF Domains Overview
All 33 SCF Domains
Search by name, code, or keyword. Filter by category. Click any card to expand its full description, related keywords, and example controls.
All 33
Governance & Management
Technical Controls
Security Operations
Data & Privacy
People & Physical
GOVERNANCE](GOV)
Security, Compliance & Resilience Governance
Execute a documented, risk-based program that supports business objectives while encompassing appropriate cybersecurity & data protection principles that addresses applicable statutory, regulatory and contractual obligations.
AAT
Artificial Intelligence and Autonomous Technology
Ensure trustworthy and resilient Artificial Intelligence (AI) and autonomous technologies to achieve a beneficial impact by informing, advising or simplifying tasks, while minimizing emergent properties or unintended consequences.
AST
Asset Management
Manage all technology assets from purchase through disposition, both physical and virtual, to ensure secured use, regardless of the asset's location.
BCD
Business Continuity & Disaster Recovery
Maintain a resilient capability to sustain business-critical functions while successfully responding to and recovering from incidents through well-documented and exercised processes.
CAP
Capacity & Performance Planning
Govern the current and future capacities and performance of technology assets.
CHG
Change Management
Manage change in a sustainable and ongoing manner that involves active participation from both technology and business stakeholders to ensure that only authorized changes occur.
CLD
Cloud Security
Govern cloud instances as an extension of on-premise technologies with equal or greater security protections than the organization's own internal cybersecurity & data privacy controls.
CPL
Compliance
Oversee the execution of cybersecurity & data privacy controls to ensure appropriate evidence required due care and due diligence exists to meet compliance with applicable statutory, regulatory and contractual obligations.
CFG
Configuration Management
Enforce secure configurations according to vendor-recommended and industry-recognized secure practices that enforce the concepts of 'least privilege' and 'least functionality' for all systems, applications and services.
MON
Continuous Monitoring
Maintain situational awareness of security-related events through the centralized collection and analysis of event logs from systems, applications and services.
CRY
Cryptographic Protections
Utilize appropriate cryptographic solutions and industry-recognized key management practices to protect the confidentiality and integrity of sensitive/regulated data both at rest and in transit.
DCH
Data Classification & Handling
Enforce a standardized data classification methodology to objectively determine the sensitivity and criticality of all data and technology assets so that proper handling and disposal requirements can be followed.
EMB
Embedded Technology
Provide additional scrutiny to reduce the risks associated with embedded technology, based on the potential damages posed from malicious use of the technology.
END
Endpoint Security
Harden endpoint devices to protect against reasonable threats to those devices and the data those devices store, transmit and process.
HRS
Human Resources Security
Execute sound hiring practices and ongoing personnel management to cultivate a cybersecurity & data privacy-minded workforce.
IAC
Identification & Authentication
Enforce the concept of "least privilege" consistently across all systems, applications and services for individual, group and service accounts through a documented and standardized Identity and Access Management (IAM) capability.
IRO
Incident Response
Maintain a viable incident response capability that trains personnel on how to recognize and report suspicious activities so that trained incident responders can take the appropriate steps to handle incidents, in accordance with a documented Incident Response Plan (IRP).
IAO
Information Assurance
Execute an impartial assessment process to validate the existence and functionality of appropriate cybersecurity & data privacy controls, prior to a system, application or service being used in a production environment.
MNT
Maintenance
Proactively maintain technology assets, according to current vendor recommendations for configurations and updates, including those supported or hosted by third-parties.
MDM
Mobile Device Management
Implement measures to restrict mobile device connectivity with critical infrastructure and sensitive/regulated data that limit the attack surface and potential data exposure from mobile device usage.
NET
Network Security
Architect and implement a secure and resilient defense-in-depth methodology that enforces the concept of 'least functionality' through restricting network access to systems, applications and services.
PES
Physical & Environmental Security
Protect physical environments through layers of physical security and environmental controls that work together to protect both physical and digital assets from theft and damage.
PRI
Data Privacy
Align data privacy practices with industry-recognized data privacy principles to implement appropriate administrative, technical and physical controls to protect regulated personal data throughout the lifecycle of systems, applications and services.
PRM
Project & Resource Management
Operationalize a viable strategy to achieve cybersecurity & data privacy objectives that establishes cybersecurity as a key stakeholder within project management practices to ensure the delivery of resilient and secure solutions.
RSK
Risk Management
Proactively identify, assess, prioritize and remediate risk through alignment with industry-recognized risk management principles to ensure risk decisions adhere to the organization's risk threshold.
SEA
Secure Engineering & Architecture
Utilize industry-recognized secure engineering and architecture principles to deliver secure and resilient systems, applications and services.
OPS
Security Operations
Execute the delivery of cybersecurity & data privacy operations to provide quality services and secure systems, applications and services that meet the organization's business needs.
SAT
Security Awareness & Training
Foster a cybersecurity & data privacy-minded workforce through ongoing user education about evolving threats, compliance obligations and secure workplace practices.
TDA
Technology Development & Acquisition
Develop and/or acquire systems, applications and services according to a Secure Software Development Framework (SSDF) to reduce the potential impact of undetected or unaddressed vulnerabilities and design flaws.
TPM
Third-Party Management
Execute Supply Chain Risk Management (SCRM) practices so that only trustworthy third-parties are used for products and/or service delivery.
THR
Threat Management
Proactively identify and assess technology-related threats, to both assets and business processes, to determine the applicable risk and necessary corrective action.
VPM
Vulnerability & Patch Management
Leverage industry-recognized Attack Surface Management (ASM) practices to strengthen the security and resilience of systems, applications and services against evolving and sophisticated attack vectors.
WEB
Web Security
Ensure the security and resilience of Internet-facing technologies through secure configuration management practices and monitoring for anomalous activity.
Universal Control Taxonomy
One Language for Every Organization
The SCF's naming convention is a core feature of the Common Controls Frameworkâ˘. Every control is identified by a three-letter domain code plus a sequential number, enabling universal, inter-organizational control language that removes ambiguity. Domain codes and control numbers are stable even as controls are updated, making version management across GRC tools reliable.
Inter-organizational standardization
Inter-organizational standardization: GOV-03 means the same thing to your organization as it does to any other SCF user, whether a vendor, assessor, regulator, or partner. That shared language is uniquely valuable.
Universal Control Taxonomy
- Domain Code: GOV
- Control Number: 03
- 3-Letter Domain Code: Identifies the control domain
- Numeric Sequence: Unique within domain
- Global Universal: Same meaning everywhere
Controls Overview
Controls are your security, compliance & resilience program - A control is the power to influence or direct behaviors and the course of events.
%20(white).png)