SCF National Cyber Parks - Procurement Pass (TDA)
The Secure Controls Framework (SCF) is focused on security, compliance & resilience capabilities.
Security + Compliance + Resilience is a unified objective. With this multi-discipline approach to cybersecurity and data protection, it signals that an organization isn’t just protected, but also meets its compliance requirements and can quickly bounce back from incidents.
The SCF is a framework and technology-agnostic approach to cybersecurity and data protection controls that can be used to identify, implement and manage secure, compliant and resilient capabilities that covers an organization’s People, Processes, Technologies, Data and Facilities (PPTDF).
As part of the SCF's cybersecurity awareness initiative, we created a National Cyber Park for each SCF domain. Of the SCF's thirty-three (33) domains, this article focuses on the Technology Development & Acquisition (TDA) domain.
Technology Development & Acquisition (TDA)
TDA Domain Principle
Develop and/or acquire systems, applications and services according to a Secure Software Development Framework (SSDF) to reduce the potential impact of undetected or unaddressed vulnerabilities and design flaws.
TDA Domain Intent
Organizations ensure that cybersecurity & data privacy principles are implemented into any products/solutions, either developed internally or acquired, to make sure that the concepts of “least privilege” and “least functionality” are incorporated.
SCF National Cyber Parks
For fans of the SCF who want some free user awareness posters, you can access this master poster that has links to each of the SCF's National Cyber Parks.

