SEF Control Domains

25 security domains across 7 control groups — a comprehensive framework built specifically for election offices.

Free tier includes 5 domains — selected as the highest-impact starting points for any election office. 1.2, 3.1, 4.3, 4.4, 6.3
Unlock All 25 Domains
01

Governance & Program Management

3 domains
1.1Security Program Establishment

Defines the overall security strategy, policies, roles, and governance structure that enable all other control domains.

Pro
1.2Security Training & Awareness Free

Ensures personnel understand security responsibilities through role-based training, phishing simulations, and ongoing awareness programs.

1.3Vendor & Third-Party Management

Evaluates and monitors the security posture of vendors, suppliers, and service providers that access or process organizational data.

Pro
02

Asset & Inventory Management

3 domains
2.1Asset Management & Control

Maintains a comprehensive inventory of hardware and software assets, tracking ownership, lifecycle, and classification throughout the organization.

Pro
2.2Configuration Management

Establishes and enforces secure baseline configurations for systems, devices, and applications, controlling changes through formal processes.

Pro
2.3AI Systems Management

Governs the acquisition, deployment, monitoring, and risk management of AI and machine learning systems, including model integrity and output validation.

Pro
03

Identity & Access Management

2 domains
3.1User Account & Identity Management Free

Manages the full lifecycle of user accounts — provisioning, authentication, privilege assignment, and deprovisioning — enforcing least privilege and separation of duties.

3.2Access Rights & Entitlement Management

Controls and regularly reviews permissions to systems, data, and functions, ensuring access remains appropriate and aligned to job responsibilities.

Pro
04

Infrastructure & Systems Protection

5 domains
4.1Network Security Management

Protects network infrastructure through segmentation, firewall management, encrypted communications, and monitoring of traffic for anomalies.

Pro
4.2Data Security & Privacy

Protects sensitive data at rest, in transit, and in use through encryption, classification, data loss prevention, and retention controls.

Pro
4.3Email & Communications Security Free

Defends messaging channels against phishing, spoofing, and malicious attachments using filtering, authentication protocols (SPF, DKIM, DMARC), and user controls.

4.4Malware & Endpoint Protection Free

Deploys and manages anti-malware, endpoint detection and response (EDR), and host-based controls to prevent, detect, and contain malicious software.

4.5Physical & Environmental Security

Controls physical access to facilities, equipment, and sensitive areas, and protects against environmental threats such as power loss, fire, and natural disaster.

Pro
05

Election Systems Security

5 domains
5.1Election Hardware Security

Ensures the physical and logical integrity of voting equipment, tabulators, and associated devices through tamper controls, chain-of-custody procedures, and pre/post-election testing.

Pro
5.2Election Software Security

Manages the integrity, version control, and testing of election management systems and voting software, including logic and accuracy testing and hash verification.

Pro
5.3Election Data Integrity & Auditability

Protects the accuracy and traceability of voter data, ballot records, and results reporting, ensuring audit trails support post-election review and certification.

Pro
5.4Polling Location Physical Security

Controls physical access to polling locations, secures ballot materials and equipment against tampering or theft, manages credentialing of election workers and observers, and establishes emergency procedures for election-day incidents.

Pro
5.5Polling Location Network Security

Secures temporary and permanent network infrastructure deployed at polling sites, including wireless access controls, network isolation of voting systems, encrypted transmission of results, and monitoring for unauthorized devices or connections.

Pro
06

Detection, Response & Recovery

4 domains
6.1Logging, Monitoring & SIEM

Collects, aggregates, and analyzes security events across systems to detect threats, support investigations, and maintain audit records.

Pro
6.2Incident Management & Response

Defines and executes procedures for identifying, containing, eradicating, and recovering from security incidents, including communication and post-incident review.

Pro
6.3Data Backup & Continuity Free

Ensures critical data and systems can be restored following disruption through tested backup procedures, recovery time objectives, and business continuity planning.

6.4Vulnerability Management & Patching

Continuously identifies, prioritizes, and remediates vulnerabilities in systems and software through scanning, patch management, and risk-based remediation workflows.

Pro
07

Security Assurance & Application Security

3 domains
7.1Application Security

Integrates security throughout the software development lifecycle, including secure coding standards, code review, dependency management, and runtime protections.

Pro
7.2Security Testing & Evaluation

Validates security controls through penetration testing, red team exercises, security assessments, and compliance audits to identify gaps before adversaries do.

Pro
7.3Compliance & Risk Management

Tracks regulatory obligations, maps controls to frameworks (NIST, CIS, CISA), and maintains a risk register to ensure continuous compliance and executive visibility.

Pro

Start Your Assessment Today

Free accounts cover 5 foundational domains. Upgrade to unlock all 25 domains and receive your Level 1 certification.