SCF Security Privacy Principles
SCF Security Privacy Principles
The C|P establishes 33 common-sense principles to guide the development and oversight of a modern cybersecurity & data privacy program. The C|P is sourced from the Secure Controls Framework (SCF), which is a free
resource for businesses. The SCF?s comprehensive listing of over 1,000 cybersecurity & data privacy controls is categorized into 33 domains that are mapped to over 100 statutory, regulatory and contractual frameworks. Those
applicable SCF controls can operationalize the C|P principles to help an organization ensure that secure practices are implemented by design and by default. Those 33 C|P principles are listed below:
2. Artificial Intelligence and Autonomous Technology (AAT) 14. Endpoint Security (END)
Ensure trustworthy and resilient Artificial Intelligence (AI) and autonomous Harden endpoint devices to protect against reasonable threats to those devices and the
technologies to achieve a beneficial impact by informing, advising or simplifying data those devices store, transmit and process.
tasks, while minimizing emergent properties or unintended consequences.
10. Continuous Monitoring (MON) 22. Physical & Environmental Security (PES)
Maintain situational awareness of security-related events through the centralized Protect physical environments through layers of physical security and environmental 31. Threat Management (THR)
collection and analysis of event logs from systems, applications and services. controls that work together to protect both physical and digital assets from theft and Proactively identify and assess technology-related threats, to both assets and
damage. business processes, to determine the applicable risk and necessary corrective action.
Copyright 2023 by Secure Controls Framework Council, LLC (SCF Council). All rights reserved.
All text, images, logos, trademarks and information contained in this document are the intellectual property of SCF Council, unless otherwise indicated. Modification of any content, including text and images, requires the prior written permission of SCF Council. Requests may be sent to [email protected].