Controls are your cybersecurity & data privacy program ---- A control is the power to influence or direct behaviors and the course of events.

NIST CSF Tiers vs SCF Maturity Model

NIST CSF Tiers vs SCF Maturity Model

Posted by SCF Council on Aug 13th 2025

The NIST Cybersecurity Framework (NIST CSF) is a popular framework to align an organization's cybersecurity practices. However, one component that is nebulous is the inclusion of Tiers in the NIST CSF, where the Tiers are often viewed as a viable Capability Maturity Model (CMM) that can be assessed …
Updated Security & Privacy Capability Maturity Model (SP-CMM)

Updated Security & Privacy Capability Maturity Model (SP-CMM)

Posted by SCF Council on Apr 25th 2023

The Secure Controls Framework (SCF) release 2023.2 contains completely new content for its Security & Privacy Capability Maturity Model (SP-CMM). This effort was conducted to help streamline and standardize maturity criteria. If you are unfamiliar with the SP-CMM, it has been around for about 4 …