SCF National Cyber Parks - Configuration Cove (CFG)
The Secure Controls Framework (SCF) is focused on security, compliance & resilience capabilities.
Security + Compliance + Resilience is a unified objective. With this multi-discipline approach to cybersecurity and data protection, it signals that an organization isn’t just protected, but also meets its compliance requirements and can quickly bounce back from incidents.
The SCF is a framework and technology-agnostic approach to cybersecurity and data protection controls that can be used to identify, implement and manage secure, compliant and resilient capabilities that covers an organization’s People, Processes, Technologies, Data and Facilities (PPTDF).
As part of the SCF's cybersecurity awareness initiative, we created a National Cyber Park for each SCF domain. Of the SCF's thirty-three (33) domains, this article focuses on the Configuration Management (CFG) domain.
Configuration Management (CFG)
CFG Domain Principle
Enforce secure configurations according to vendor-recommended and industry-recognized secure practices that enforce the concepts of “least privilege” and “least functionality” for all systems, applications and services.
CFG Domain Intent
Organizations establish and maintain the integrity of systems. Without properly documented and implemented configuration management controls, security features can be inadvertently or deliberately omitted or rendered inoperable, allowing processing irregularities to occur or the execution of malicious code.
SCF National Cyber Parks
For fans of the SCF who want some free user awareness posters, you can access this master poster that has links to each of the SCF's National Cyber Parks.

