Secure Controls Framework

1,534 controls across 34 domains

Source: SCF 2026.2About SCF
securecontrolsframework.com
Back to catalog
END-16ENDEndpoint Security

Restrict Access To Security Functions

Description

Mechanisms exist to ensure security functions are restricted to authorized individuals and enforce least privilege control requirements for necessary job functions.

Cross-Mappings

174 paths across 3 frameworks
NIST 800-531 mapping
SC-3
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI1 mapping
CCI-001084
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
STIG110 mappings
SV-203656r958518_ruleThe operating system must isolate security functions from nonsecurity functions.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205521r961131_ruleThe Mainframe Product must isolate security functions from nonsecurity functions.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205714r958518_ruleWindows Server 2019 administrator accounts must not be enumerated during elevation.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205715r958518_ruleWindows Server 2019 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205716r958518_ruleWindows Server 2019 UIAccess applications must not be allowed to prompt for elevation without using the secure desktop.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205717r958518_ruleWindows Server 2019 User Account Control must, at a minimum, prompt administrators for consent on the secure desktop.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205718r958518_ruleWindows Server 2019 User Account Control must be configured to detect application installations and prompt for elevation.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205719r958518_ruleWindows Server 2019 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-205720r958518_ruleWindows Server 2019 User Account Control (UAC) must virtualize file and registry write failures to per-user locations.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-206408r961131_ruleThe web server document directory must be in a separate partition from the web servers system files.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 4 · disa_xccdf · related

+100 more (top 10 by confidence shown)

Control mappings provided by the Secure Controls Framework (SCF).

SCF

Powered by the Secure Controls Framework

The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.

© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer