Controls are your cybersecurity & data privacy program ---- A control is the power to influence or direct behaviors and the course of events.

NIST CSF Tiers vs SCF Maturity Model

NIST CSF Tiers vs SCF Maturity Model

Posted by SCF Council on Aug 13th 2025

The NIST Cybersecurity Framework (NIST CSF) is a popular framework to align an organization's cybersecurity practices. However, one component that is nebulous is the inclusion of Tiers in the NIST CSF, where the Tiers are often viewed as a viable Capability Maturity Model (CMM) that can be assessed …
NIST CSF 2.0 Assessment Guide

NIST CSF 2.0 Assessment Guide

Posted by SCF Council on Aug 12th 2025

This NIST Cybersecurity Framework 2.0 (NIST CSF 2.0) assessment guide is designed for organizations that align with the cybersecurity governance framework established by NIST CSF 2.0. This is ideal for organizations that want to demonstrate conformity with NIST CSF 2.0 through a third-party assessme …
Cybersecurity MA&D Standards

Cybersecurity MA&D Standards

Posted by SCF Council on Jul 29th 2025

The Secure Control Framework Council (SCF Council) established a cohesive, consistent set of standards for evaluating relevant cybersecurity and data protection-related controls as part of Mergers, Acquisitions & Divestitures (MA&D) due diligence activities. This MA&D due diligence is as …