Back to catalog
GOV-02GOVSecurity, Compliance & Resilience Governance
Publishing Security, Compliance & Resilience Documentation
Description
Mechanisms exist to establish, maintain and disseminate policies, standards and procedures necessary for secure, compliant and resilient capabilities.
Cross-Mappings
8668 paths across 4 frameworks
Cross-Mappings
NIST 800-5320 mappings
AC-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
AT-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
AU-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
CA-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
CM-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
CP-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
IA-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
IR-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
MA-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
MP-1
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
+10 more (top 10 by confidence shown)
NIST 800-1715 mappings
3.13.1
0.25
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · subset
- Secure Controls Framework · 2026.2 · scf_strm · related
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.13.2
0.25
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · subset
- Secure Controls Framework · 2026.2 · scf_strm · related
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.14.6
0.25
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · subset
- Secure Controls Framework · 2026.2 · scf_strm · related
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.14.7
0.25
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · subset
- Secure Controls Framework · 2026.2 · scf_strm · related
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.7.5
0.13
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · related
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI635 mappings
CCI-000001
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000002
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000003
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000004
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000005
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000006
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000073
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000074
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000075
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000076
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
+625 more (top 10 by confidence shown)
STIG10 mappings
SV-239862r953982_ruleThe Cisco ASA must be configured to send log data of denied traffic to a central audit server for analysis.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V2R1 · disa_xccdf · related
SV-243442r991589_ruleAdministrators of high-value IT resources must complete required training.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-251654r1028319_ruleCA IDMS must use pervasive encryption to cryptographically protect the confidentiality and integrity of all information at rest in accordance with data owner requirements.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V2R1 · disa_xccdf · related
SV-256877r958482_ruleIndividual user accounts with passwords must be maintained for the Hardware Management Console operating system and application.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V2R1 · disa_xccdf · related
SV-259903r948747_ruleAn inventory of authorized instruments must be documented and maintained in support of the detection of unauthorized instruments connected to the Enterprise Voice, Video, and Messaging system.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 1 · disa_xccdf · related
SV-259904r948748_ruleCustomers of the DISN VoSIP service must use address blocks assigned by the DRSN/VoSIP PMO.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 1 · disa_xccdf · related
SV-259905r948749_ruleVoice networks must not be bridged via a Unified Capability (UC) soft client accessory.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 1 · disa_xccdf · related
SV-259906r948750_ruleWhen soft-phones are implemented as the primary voice endpoint in the user's workspace, a policy must be defined to supplement with physical hardware-based phones near all such workspaces.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 1 · disa_xccdf · related
SV-259907r948751_ruleImplementing Unified Capabilities (UC) soft clients as the primary voice endpoint must have authorizing official (AO) approval.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 1 · disa_xccdf · related
SV-259908r948752_ruleDeploying Unified Capabilities (UC) soft clients on DOD networks must have authorizing official (AO) approval.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 1 · disa_xccdf · related
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer