Secure Controls Framework
Download The SCF

Overlapping Cybersecurity Regulations: How One Common Control Set Cuts Duplicate Compliance Work

Compliance,Metaframework,Secure Controls Framework,Controls
SCF Council
•

Overlapping cybersecurity regulations force many organizations to run the same controls through several separate compliance programs. A Common Controls Framework (CCF) solves this by defining one set of controls, mapping each control to every law, regulation and framework that requires it, and letting teams implement and assess once while showing compliance to many requirements at the same time.

Why are overlapping cybersecurity regulations a growing problem?

Cybersecurity Dive reported on a GAO report that collected industry feedback on overlapping cybersecurity regulations. According to that article, representatives from the energy, finance and healthcare sectors described duplicative or conflicting rules, including differences between TSA and NERC requirements, between NCUA and GLBA or FTC Safeguards expectations, and between HIPAA, SEC and CISA incident reporting definitions. The article also notes GAO's view that progress on harmonization "has been limited."

For a security team, the practical cost is easy to recognize: the same access control, incident response and vendor oversight practices get documented, evidenced and audited several times, each time in a different vocabulary.

This is exactly what the Secure Controls Framework (SCF) is designed to address - one control set that is built to help organizations be secure, compliant and resilient in the most efficient and scalable manner possible.

What is a Common Controls Framework (CCF)?

A Common Controls Framework (CCF) is a single catalog of controls that sits above individual laws, regulations and frameworks. Instead of building a separate program for each obligation, an organization implements the common controls and uses mappings to show which requirements each control addresses. The Secure Controls Framework (SCF) is a free Common Controls Framework with 1,500+ controls organized into 34 domains and mapped to 200+ laws, regulations and frameworks.

How does one set of controls satisfy many requirements?

The work happens in the mappings. The SCF uses NIST IR 8477 Set Theory Relationship Mapping (STRM) to describe how each SCF control relates to each external requirement: equal to, subset of, superset of, intersects with, or no relationship, with a strength rating. You can read how this works on the STRM page. Based on how the relationships are explicit, a team can see where one control fully covers a requirement and where a gap remains.

common controls framework crosswalk mapping

How do you start consolidating overlapping compliance programs?

  1. List your obligations. Write down every law, regulation, contract and framework that applies to you. Sort them into statutory, regulatory and contractual requirements.
  2. Download the SCF and filter. Use the free SCF download and filter the mapping columns to the obligations on your list. The controls that remain are your control set.
  3. Assign owners once. Each control gets one owner and one set of evidence, no matter how many requirements it supports.
  4. Assess once, report many ways. Use the mappings to produce the views each regulator, auditor or customer needs from the same evidence.

The Secure, Compliant & Resilient Management System (SCRMS) goes into significant detail about how to utilize a Common Controls Framework (CCF) to efficiently address overlapping compliance obligations.

Does harmonization from regulators remove the need for this?

Not on its own. Even where regulators align definitions, organizations still answer to contracts, customer questionnaires and voluntary frameworks. A common control set gives you a stable internal structure that does not depend on how quickly external requirements converge.

Common Control Framework Frequently Asked Questions (FAQ)

Is a common controls framework a replacement for laws and regulations?

No. Laws and regulations still apply. A common controls framework is an implementation layer that shows how one set of controls addresses many of those requirements.

Is the Secure Controls Framework (SCF) free?

Yes. The SCF Council publishes the SCF at no cost under a Creative Commons license, and it can be downloaded from the SCF website.

What is STRM?

Set Theory Relationship Mapping is the crosswalk method described in NIST IR 8477. The SCF uses it to state how each SCF control relates to each mapped requirement.

Can one assessment cover several frameworks?

Yes. The SCR Conformity Assessment Program describes assessments against SCF-based control sets that can demonstrate conformity with several frameworks in one engagement.