SCF National Cyber Parks - Assurance Summit (IAO)
The Secure Controls Framework (SCF) is focused on security, compliance & resilience capabilities.
Security + Compliance + Resilience is a unified objective. With this multi-discipline approach to cybersecurity and data protection, it signals that an organization isn’t just protected, but also meets its compliance requirements and can quickly bounce back from incidents.
The SCF is a framework and technology-agnostic approach to cybersecurity and data protection controls that can be used to identify, implement and manage secure, compliant and resilient capabilities that covers an organization’s People, Processes, Technologies, Data and Facilities (PPTDF).
As part of the SCF's cybersecurity awareness initiative, we created a National Cyber Park for each SCF domain. Of the SCF's thirty-three (33) domains, this article focuses on the Information Assurance (IAO) domain.
Information Assurance (IAO)
IAO Domain Principle
Execute an impartial assessment process to validate the existence and functionality of appropriate cybersecurity & data privacy controls, prior to a system, application or service being used in a production environment.
IAO Domain Intent
Organizations ensure the adequacy of cybersecurity & data privacy controls in development, testing and production environments.
SCF National Cyber Parks
For fans of the SCF who want some free user awareness posters, you can access this master poster that has links to each of the SCF's National Cyber Parks.

