SCF National Cyber Parks - Access Control Arch (IAC)
The Secure Controls Framework (SCF) is focused on security, compliance & resilience capabilities.
Security + Compliance + Resilience is a unified objective. With this multi-discipline approach to cybersecurity and data protection, it signals that an organization isn’t just protected, but also meets its compliance requirements and can quickly bounce back from incidents.
The SCF is a framework and technology-agnostic approach to cybersecurity and data protection controls that can be used to identify, implement and manage secure, compliant and resilient capabilities that covers an organization’s People, Processes, Technologies, Data and Facilities (PPTDF).
As part of the SCF's cybersecurity awareness initiative, we created a National Cyber Park for each SCF domain. Of the SCF's thirty-three (33) domains, this article focuses on the Identification & Authentication (IAC) domain.
Identification & Authentication (IAC)
IAC Domain Principle
Enforce the concept of “least privilege” consistently across all systems, applications and services for individual, group and service accounts through a documented and standardized Identity and Access Management (IAM) capability.
IAC Domain Intent
Organizations implement the concept of “least privilege” through limiting access to the organization's systems and data to authorized users only.
SCF National Cyber Parks
For fans of the SCF who want some free user awareness posters, you can access this master poster that has links to each of the SCF's National Cyber Parks.

