Controls are your cybersecurity & data privacy program ---- A control is the power to influence or direct behaviors and the course of events.

SCF Risk & Threat Catalog

SCF Risk & Threat Catalog

Posted by SCF Council on Jan 19th 2023

In addition to cybersecurity and privacy controls, the Secure Controls Framework (SCF) contains a separate risk and threat catalog, which have mappings to applicable SCF controls. These risk and threat catalogs are also leveraged within the Security & Privacy Risk Management Model (SP-RMM) that …
Let's Talk About Evidence - Evidence Request List (ERL)

Let's Talk About Evidence - Evidence Request List (ERL)

Posted by SCF Council on Nov 2nd 2022

The SCF's Evidence Request List (ERL) is designed to standardize and streamline the evidence request process for an assessment. This is going to be utilized as part of the SCF's Conformity Assessment Program (CAP) to identify reasonably-expected artifacts/evidence to meet applicable SCF controls (it …