Complete disposal
Data is removed from primary systems, backups, caches, exports and third parties when it is no longer needed or on request.
DTCF normalises what an organization must achieve into 7 objectives across 10 families, then maps each to the frameworks practitioners face. Mappings are graded: fully addressed, partially addressed, or deliberately absent with the reason recorded. An empty cell is a finding about the framework, not a gap in your programme.
DTCF 2026.1 · published 10 Sep 2026 · CC BY 4.0 · free to use with attribution
Data is removed from primary systems, backups, caches, exports and third parties when it is no longer needed or on request.
Entitlements are reviewed by someone who can judge them, with revocations tracked to completion.
Authentication is proportionate to risk, with multi-factor authentication on administrative and remote access.
Administrative access is limited, separately approved, monitored and time-bound where possible.
Devices with access to organizational data are hardened, patched, encrypted and recoverable.
Reportable incidents are assessed and notified to regulators and affected people within the applicable deadlines.
Where a control is tested by sample, the population is defined and its completeness can be demonstrated.
First edition. Objectives are normalised statements of what an organization must achieve. Mappings are graded: full, partial, or a recorded absence with the reason it is absent. An empty cell is a finding about the framework, not about the objective.
Framework names and references are the property of their publishers. DTCF is an independent mapping and is not endorsed by them. Corrections are welcome through the contact form and are published in the edition changelog.