A Guide To All 34 Secure Controls Framework (SCF) Domains
The SCF solves the issue of disorganized control sets from a multitude of requirements by giving every control a home in a hierarchical structure.
This is a great starting point for those new to the SCF, since this will help explain what each domain governs, the operational problemit exists to solve and why it warrants dedicated discipline rather than beingabsorbed into a neighboring domain.
This is not an introduction to security frameworks; it is a reference for practitioners who want to understand the SCF's structure and use, since the target reader already understands basic GRC concepts.
The SCF maps to over 200 laws, regulations and frameworks, including NIST SP 800-53, NIST 800-171, ISO 27001, SOC 2, CMMC, HIPAA and many others. That cross-mapping is one of its core value propositions: organizations can use the SCF as a single authoritative control set and derive compliance evidence for multiple frameworks from it. Understanding each domain is the prerequisite to using that capability well.
How The SCF’s Domains Work Together
The SCF's value is not in any single domain but in how the 34 domains form a complete control architecture when implemented together. The dependencies between domains are structural. Asset Management (AST) is a prerequisite for Vulnerability Management (VPM), Configuration Management (CFG) and Continuous Monitoring (MON): you cannot secure, configure, or monitor assets you haven't inventoried. Data Classification (DCH) is a prerequisite for Data Privacy (PRI), Cryptographic Protections (CRY) and data handling decisions across the framework: knowing what's sensitive determines what protection level applies. Risk Management (RSK) provides the prioritization logic that determines where to invest across all 34 domains.
The cross-mapping capability is where this structure paysoff for practitioners. An organization using the SCF as its authoritativecontrol framework can identify which controls satisfy which requirements acrossNIST 800-53, NIST 800-171 ISO 27001, SOC 2, CMMC, PCI DSS, HIPAA and otherssimultaneously. Instead of maintaining separate control sets for eachframework, the organization maintains one set and derives compliance evidencefrom it. That requires understanding each domain well enough to know what controlsit contains and what evidence those controls produce.
For GRC practitioners, the 34-domain structure provides aclear audit scope. Every domain has a defined principle and intent, which meansassessors can evaluate whether controls are designed to address the principleand operating to fulfill the intent. For CISOs, the structure provides aboard-communicable program map: each domain is a funded, owned disciplinerather than a control spreadsheet that only security engineers can interpret.
The SCF is not the only framework that organizes controlsinto domains. What distinguishes it is the consistency of the domain structureacross security, privacy and resilience, combined with the cross-mapping to abroad set of regulatory requirements. Practitioners who understand eachdomain's scope and dependencies can use the framework to manage complexcompliance environments without maintaining a separate program for eachrequirement they face.
That is the SCF's operational case: one framework, onecontrol set, evidence reusable across frameworks. The 34 domains are thearchitecture that makes that possible:
One Language for Every Organization
The SCF's naming convention is integral to the Common Controls Framework™, providing a standardized approach to control identification. Each control is marked by a unique three-letter domain code followed by a sequential number. This system ensures a consistent, universal language across organizations, eliminating confusion and enhancing communication. The stability of domain codes and control numbers, even amidst updates, facilitates reliable version management in Governance, Risk, and Compliance (GRC) tools.
Inter-organizational standardization
Inter-organizational standardization: GOV-03 means the same thing to your organization as it does to any other SCF user, whether a vendor, assessor, regulator, or partner. That shared language is uniquely valuable.
Learn More About All The SCF Domains
Below, you can read more about all of the SCF's 34 domains in greater detail.
Govern Artificial Intelligence & Autonomous Technologies (AAT) through trustworthy, secure and resilient lifecycle practices that manage intended and unintended outcomes.
Manage Technology Assets, Applications and Services (TAAS) throughout their lifecycle to maintain visibility, accountability, authorization and protection.
Maintain resilient capabilities to sustain business-critical functions and recover from disruptions through documented, tested and maintained continuity and recovery processes.
Govern current and future capacity and performance requirements for Technology Assets, Applications, Services and Data (TAASD) to sustain reliable operations.
Manage changes to Technology Assets, Applications, Services and Data (TAASD) through an authorized, risk-based process that evaluates, implements and validates changes before and after deployment.
Govern cloud services and environments through risk-based, cloud-native security, compliance and resilience practices aligned with shared responsibility obligations.
Govern security, compliance and data protection obligations to maintain defensible evidence of conformity with applicable internal and external requirements.
Establish and enforce secure configuration baselines that implement least privilege and least functionality for Technology Assets, Applications and Services (TAAS) to support a defensible secure configuration posture.
Maintain situational awareness through centralized collection, correlation and analysis of security-relevant telemetry from Technology Assets, Applications and Services (TAAS).
Use appropriate cryptographic mechanisms and industry-recognized key management practices to protect sensitive and regulated data at rest and in transit.
Enforce a standardized classification methodology to determine data sensitivity and support Technology Assets, Applications and Services (TAAS) criticality decisions, enabling appropriate data handling, protection, retention and disposal requirements.
Execute risk-based and legally defensible data privacy practices that conform with applicable statutory, regulatory and contractual obligations to protect sensitive Personal Data (sPD) throughout its lifecycle.
Apply risk-based security, compliance and resilience practices to embedded technologies where compromise or misuse could create operational, safety and/or data protection impacts.
Harden and centrally manage endpoint devices to protect Technology Assets, Applications, Services and Data (TAASD) from unauthorized access, compromise and disruption.
Execute security-informed personnel management practices that address screening, onboarding, acceptable behavior, role-based risk, competence and offboarding requirements.
Implement secure, compliant and resilient Identity and Access Management (IAM) capabilities that enforce least privilege across human users, devices, service accounts and other Non-Person Entities (NPEs).
Maintain a tested incident response capability that enables trained responders to identify, analyze, contain, eradicate and recover from incidents according to documented Incident Response Plans (IRPs).
Execute Information Assurance (IA) practices to validate that expected security, compliance and resilience controls are appropriately designed and operating as intended for Technology Assets, Applications and Services (TAAS).
Proactively maintain Technology Assets, Applications and Services (TAAS) through authorized maintenance practices that preserve performance, security, compliance, resilience and supportability.
Govern mobile device access to Technology Assets, Applications, Services and Data (TAASD) to reduce attack surface and data exposure.
Architect and implement defense-in-depth network protections that segment, restrict and monitor access to Technology Assets, Applications, Services and Data (TAASD).
Protect physical environments through layered physical security and environmental controls that safeguard physical and digital assets from unauthorized access, theft, damage and disruption.
Operationalize security, compliance and resilience objectives by integrating cybersecurity and data privacy requirements into project, program and resource management practices.
Mitigate quantum-enabled cryptographic risks through governance structures that operationalize Post-Quantum Cryptography (PQC) risk management practices.
Proactively identify, assess, prioritize and treat risks to align Technology Assets, Applications, Services and Data (TAASD)-related decisions with the organization's defined risk appetite and risk tolerance.
Apply industry-recognized secure engineering and architecture principles to deliver secure, compliant and resilient systems, applications and services.
Foster a security, compliance and resilience-minded workforce through ongoing, role-based education on evolving threats, obligations and secure workplace practices.
Govern the organization’s Security, Compliance & Resilience Program (SCRP) through accountable oversight, evidence-based decision-making and defensible evidence that the organization is secure, compliant and resilient.
Deliver secure, compliant and resilient operations through defined processes, skilled personnel, monitoring, escalation and continuous improvement that effectively detect, isolate, and remediate cyber threats while ensuring business resilience.
Develop and acquire Technology Assets, Applications and Services (TAAS) through secure-by-design, risk-informed and resilient lifecycle practices.
Execute Supply Chain Risk Management (SCRM) practices to assess, select, contract, monitor and manage trustworthy third parties for product and service delivery.
Proactively identify, assess and manage threats to Technology Assets, Applications, Services and Data (TAASD) and business processes to inform risk decisions and corrective actions.
Reduce exploitable weaknesses in Technology Assets, Applications and Services (TAAS) through coordinated vulnerability identification, prioritization, remediation and validation practices.
Protect Internet-facing Technology Assets, Applications and Services (TAAS) by minimizing attack surfaces and monitoring for anomalous activity.
What To Explore Next
Included Laws & Frameworks
See every law, regulation, and framework mapped into the SCF, from NIST CSF to GDPR to PCI DSS.
Set Theory Relationship Mapping (STRM)
How NIST IR 8477 STRM methodology makes SCF control mappings mathematically transparent and defensible.
Download the SCF
Get the full SCF with all 34 domains, 1,500+ controls, and 200+ framework mappings, free forever.
.png)

%20(white).png)