Secure Controls Framework
Download The SCF

Frequently Asked Questions (FAQ)

Everything you need to know about the Secure Controls Framework® (SCF), the Common Controls Framework™, from getting started and understanding the metaframework to SCF CAP certification, licensing, and implementation.

General

About the Secure Controls Framework®

Foundational questions about what the SCF is, why it exists, and what makes it different from other cybersecurity frameworks.

What Is The SCF?

The SCF stands for the Secure Controls Framework. It is more than just an assortment of cybersecurity and data privacy controls. It is focused on designing, implementing and maintaining secure, compliant, and resilient capabilities to address all applicable statutory, regulatory and contractual requirements that an organization faces.

Our belief is that if you scope your requirements with security in mind, compliance will generally be a natural byproduct of those secure and resilient actions. We want organizations to be secure, compliant and resilient, since it benefits all of modern society.

Why Does The SCF Say It Is The Common Controls Framework?

The use of Common Controls Framework™ is trademarked and the SCF has exclusive rights to use the term. The SCF is the Common Controls Framework™ (CCF) because in addition to providing a common set of controls that organizations use to satisfy multiple compliance obligations simultaneously through a single, unified control set, the SCF owns the domains commoncontrolsframework.com and common-controls-framework.com.

What Is A Metaframework?

A "metaframework" is a framework of frameworks. That is exactly what the SCF is. It is a framework made up of over 200 cybersecurity and data privacy laws, regulations and frameworks. Rather than implementing each framework separately, the SCF provides a single comprehensive control set that maps to all of them simultaneously.

How Is The SCF Different From NIST, ISO 27001, or CIS Controls?

NIST CSF, ISO 27001, and CIS Critical Security Controls are individual cybersecurity frameworks. The SCF is a metaframework that encompasses all of them, and over 200 others. When you implement the SCF, you are implementing the common controls that satisfy NIST, ISO, CIS, and many other frameworks simultaneously.

This eliminates the need to maintain separate control sets for each framework, regulation, or law your organization must comply with. The SCF’s Set Theory Relationship Mapping (STRM) methodology ensures these mappings are mathematically rigorous, not subjective crosswalks.

How Often Is The SCF Updated?

The general cadence for updates is one (1) update per quarter. There may be situations where out-of-cycle updates are released, but the goal is to publish updates on a quarterly basis. The SCF is a Living Control Set, meaning it is continuously maintained and updated to reflect changes in the regulatory landscape.

Does The SCF Cover Artificial Intelligence (AI)?

Yes. The SCF has had coverage for AI since 2024. The Artificial Intelligence & Autonomous Technologies (AAT) domain is one of thirty-three domains in the SCF. That domain has coverage for these AI-specific requirements:

  • ISO 42001
  • NIST AI Risk Management Framework
  • NIST 600-1 (Generative AI)
  • EU AI Act
Getting Started

How To Start Using The SCF

Practical questions about downloading, implementing, and operationalizing the SCF in your organization.

Where Do I Start?

The best place to begin is the Start Here page. It provides a guided introduction to the Secure Controls Framework, what it is, how it works, and how to begin using it in your organization. The page walks you through the SCF's structure, its 33 domains, the metaframework concept, and links to the key resources you'll need.

  1. Read the Start Here Guide: The SCF Recommended Practices (PDF) gives you a concise overview of how to get started.
  2. Understand the SCRMS: The Security, Compliance & Resilience Management System is the SCF's implementation methodology, your roadmap for building an SCF-based program.
  3. Download the SCF: Grab the free Excel, CSV, or NIST OSCAL JSON version from the SCF Download page and start tailoring controls to your needs.

How Do I Use The SCF?

Start by reading the "What Is The SCF" page, which includes a Start Here Guide for recommended practices.

To build an SCF-based cybersecurity program, begin with the Security, Compliance & Resilience Management System (SCRMS) and the SCRMS Prioritized Implementation Guide (SCRMS-PIG). These provide a "paint by numbers" approach to creating a tailored, prioritized set of controls.

Once ready to start working with the SCF, you can either:

  1. Download the Excel version from the SCF Download page and create your own control set; or
  2. Use a GRC platform like SCF Connect or others listed on the SCF Marketplace.

What Is The SCRMS And Why Does It Matter?

The Security, Compliance & Resilience Management System (SCRMS) is the SCF’s implementation methodology. It provides the structured approach for designing, building, and maintaining a cybersecurity program using the SCF. Think of it as the "how to" guide for turning SCF controls into an operational program.

The SCRMS covers the full lifecycle: scoping, tailoring controls, implementing, operating, and continuously improving your program across the People, Process, Technology, Data, and Facilities (PPTDF) dimensions.

What Does “Mechanisms Exist” Mean In SCF Controls?

The SCF controls are written to be flexible for organizations of any size or industry. The term "mechanism" can mean a manual process, technology solution, or anything in between. If you prefer different wording, you can replace "mechanism" with "solution," "processes," or another term that fits your organization’s context.

The key point is that a mechanism demonstrates that the control requirement is being addressed, whether through a documented procedure, an automated tool, or a combination of both.

What If I Get Stuck And Need Help?

If you need assistance with tailoring or operationalizing the SCF, there are several options:

Controls & Domains

SCF Controls, Domains & Structure

Questions about the SCF’s control structure, domain organization, risk model, maturity model, and how controls work in practice.

How Many Controls Does The SCF Have?

The SCF contains over 1,400 controls across 33 domains. These controls are mapped to over 200 cybersecurity and data privacy laws, regulations, and frameworks. The SCF is a comprehensive catalog. You are not expected to implement all 1,400+ controls. The tailoring process helps you select only the controls applicable to your organization.

What Are The 33 SCF Domains?

The SCF is organized into 33 control domains that cover every aspect of cybersecurity and data protection. These range from Governance (GOV) and Risk Management (RSK) to specialized domains like Artificial Intelligence & Autonomous Technologies (AAT), Supply Chain Risk Management (SCR), and Web Security (WEB). You can explore the full list on the SCF Domains & Principles page.

What Are Assessment Objectives (AOs)?

Assessment Objectives (AOs) are the specific, testable criteria used to evaluate whether a control is appropriately designed, properly implemented, and producing the desired security outcome. Each SCF control has one or more AOs that assessors use during SCF CAP conformity assessments.

AOs are defined in the Cybersecurity & Data Protection Assessment Standards (CDPAS), which is free to download.

What Is The SCF Risk Model (SCR-RMM)?

The Security, Compliance & Resilience Risk Management Model (SCR-RMM) is the SCF’s free, integrated risk model. It provides a structured approach to identifying, analyzing, and managing cybersecurity and data privacy risks at the control level. Rather than treating risk management as a separate exercise, the SCR-RMM embeds risk directly into the SCF’s control structure.

The SCR-RMM maps specific risks and threats to each SCF control, giving organizations a clear view of what could go wrong if a control is absent or inadequate. This enables risk-informed decision-making when tailoring and prioritizing controls. You can see exactly which risks you are accepting, mitigating, or transferring for every control in your program.

The SCR-RMM is available as a free download from the SCR-RMM page.

What Is The SCF Maturity Model (SCR-CMM)?

The Security, Compliance & Resilience Capability Maturity Model (SCR-CMM) is the SCF’s free maturity model that allows organizations to measure and benchmark the maturity of their cybersecurity and data privacy practices at the control level. It provides quantifiable maturity criteria for each SCF control across defined maturity levels.

The SCR-CMM helps organizations answer the question "how good are we?" by providing a consistent scale for evaluating People, Processes, and Technology (PPT) across every control. This supports capability gap analysis, investment prioritization, and board-level reporting on cybersecurity program maturity over time.

The SCR-CMM is available as a free download from the SCR-CMM page.

How Do You Define Cybersecurity Materiality?

Cybersecurity materiality is the concept of determining which cybersecurity and data privacy risks are significant enough to warrant attention, investment, and disclosure. Drawing from the financial auditing concept of materiality, it applies the same principle to cybersecurity: not every risk is equal, and organizations must determine which risks, if left unaddressed, could materially impact the business.

The SCF addresses cybersecurity materiality as a GRC Fundamentals topic. In practice, this means defining thresholds for what constitutes a "material" cybersecurity risk or deficiency in your organization, which informs control scoping, investment decisions, board reporting, and regulatory disclosure obligations (e.g., SEC cybersecurity incident disclosure rules).

Materiality is particularly relevant for organizations subject to regulatory disclosure requirements, public companies, and any organization communicating cybersecurity posture to stakeholders, investors, or regulators.

Metaframework & Mapping

Metaframework Methodology & STRM Mapping

How the SCF maps to 200+ laws, regulations, and frameworks using rigorous Set Theory Relationship Mapping.

How Does The SCF Map To 200+ Frameworks?

The SCF uses Set Theory Relationship Mapping (STRM), a mathematically rigorous methodology based on NIST IR 8477, to map controls to external frameworks, laws, and regulations. Unlike subjective crosswalks, STRM uses set theory to define the precise relationship between SCF controls and external requirements, producing mappings that are accurate, consistent, and defensible.

What Is STRM And Why Does It Matter?

Set Theory Relationship Mapping (STRM) is the gold standard for crosswalk mapping between cybersecurity and data privacy requirements. It replaces subjective "best guess" crosswalks with a mathematical model that precisely defines the relationship between controls and external requirements.

The SCF is a recognized NIST OLIR Program participant with accepted mappings between the SCF and NIST frameworks.

What Laws, Regulations & Frameworks Does The SCF Cover?

The SCF maps to over 200 laws, regulations, and frameworks including NIST CSF, NIST 800-53, NIST 800-171, ISO 27001/27002, CIS Controls, CMMC, HIPAA, GDPR, PCI DSS, SOC 2 TSC, CCPA/CPRA, NIS2, DORA, FedRAMP, SOX, GLBA, and many more. The complete list is available on the Included Laws, Regulations & Frameworks (LRF) page.

Licensing & Cost

Licensing, Cost & Usage Rights

Questions about why the SCF is free, what the Creative Commons license allows, and commercial licensing options.

Why Is The SCF Free To Use?

The SCF is free to help fix the broken nature of cybersecurity and data protection practices in many organizations. The quality of the SCF could easily justify a costly subscription service, but that would exclude most organizations and defeat the broader goal of improving cybersecurity and privacy practices on a macro scale.

The SCF’s contributors are volunteers, and the project relies on generous sponsors to maintain the framework.

Are There Restrictions On The Use Of The SCF?

The SCF is copyrighted material that uses the Creative Commons licensing model to keep it free for businesses to use. The Terms & Conditions page details the open license granted for organizational use. There are options for commercial licenses for companies that want to create derivative content based on the SCF.

Technical & Formats

SCF Conformity Assessment Program

Questions about SCF CAP certification for organizations, including assessment methodology, 3PAOs, and The CyberAB.

What Is The SCF CAP?

The SCF Conformity Assessment Program (SCF CAP) is the organization-level certification program that allows organizations to demonstrate conformity with SCF-based cybersecurity and data protection requirements. Assessments are conducted by accredited Third-Party Assessment Organizations (3PAOs) using the examine, interview, and test (EIT) methodology.

What Is The CyberAB?

The CyberAB is the official Accreditation Body (AB) for the SCF Conformity Assessment Program (SCF CAP). The CyberAB accredits 3PAOs, maintains the SCF Marketplace, and oversees the accreditation standards that ensure assessment quality and independence.

What Are SCF Assessment Guides?

SCF Assessment Guides are pre-built, ready-to-use assessment packages that define the specific set of controls an organization must implement and be assessed against for a particular compliance objective (e.g., NIST CSF 2.0, CMMC Level 1, HIPAA). Each guide maps to the relevant SCF controls and Assessment Objectives for that certification track.

Get Started With The SCF

SCF Training & Individual Certifications

Questions about the three SAICO individual certification tracks and how to get certified.

What Is SAICO?

SAICO is the SCF Assessor and Instructor Certification Organization. SAICO provides three Computer-Based Training (CBT) certification programs for individuals: SCF Practitioner (foundation), SCF Architect (design & implementation), and SCF Assessor (assessment & audit).

What Are The Three SAICO Certification Levels?

The three SAICO certification tracks are:

  1. SCF Practitioner: Foundation level. Implement and maintain SCF-based controls. No prerequisites.
  2. SCF Architect: Intermediate level. Design and architect SCF-based programs. Builds on Practitioner knowledge.
  3. SCF Assessor: Advanced level. Lead or participate in 3PAO assessment teams conducting SCF CAP conformity assessments.

All three are delivered via self-paced CBT through the SCF Training Platform.

Marketplace & Ecosystem

SCF Marketplace & Ecosystem Partners

Questions about the SCF partner ecosystem, marketplace participants, and how to find SCF expertise.

What Is The SCF Marketplace?

The SCF Marketplace connects organizations with SCF expertise. It includes six categories of ecosystem participants: 3PAOs (assessment organizations), ASPs (solution providers), RPOs (consulting providers), ACIs (control integrators), LTPs (training providers), and LCPs (content providers). The authoritative listing is maintained by The CyberAB.

What Is SCF Connect?

SCF Connect is the SCF-specific GRC platform built from the ground up to operationalize the Secure Controls Framework. It is the official Single Source of Truth (SSOT) for SCF CAP third-party conformity assessments. SCF Connect is priced at $200/month and provides an intuitive SaaS platform for implementing, managing, and reporting on SCF-based cybersecurity programs.

Contact Us

Download Formats & Technical Details

Questions about the SCF download formats, NIST OSCAL support, and technical integration options.

What Formats Is The SCF Available In?

The SCF is available for free download in multiple formats:

  • Microsoft Excel (.xlsx): The primary format for working with SCF controls, tailoring, and GRC import.
  • CSV (.csv): For programmatic import into GRC platforms and databases.
  • NIST OSCAL JSON: Machine-readable format following the NIST Open Security Controls Assessment Language standard for automated processing.

What Is NIST OSCAL And Why Does The SCF Support It?

NIST OSCAL (Open Security Controls Assessment Language) is a standardized, machine-readable format for representing cybersecurity controls, assessment results, and system security plans. The SCF supports OSCAL JSON to enable automated ingestion by GRC platforms, security tooling, and compliance automation systems, eliminating manual data entry and enabling continuous compliance monitoring.

What Free Content Does The SCF Provide Besides The Controls?

The SCF provides a comprehensive library of free content beyond the control catalog:

  • SCR-RMM: Security, Compliance & Resilience Risk Management Model
  • SCR-CMM: Security, Compliance & Resilience Capability Maturity Model
  • CDPAS : Cybersecurity & Data Protection Assessment Standards
  • ERL : Evidence Request List for assessments
  • USG : Unified Scoping Guide
  • DPMP : Data Privacy Management Principles
  • MA&D: Mergers, Acquisitions & Divestitures security guidance
Additional Questions

Additional Frequently Asked Questions (FAQs)

What is OSCAL and which frameworks support it?
The Secure Controls Framework supports OSCAL, the Open Security Controls Assessment Language. Each SCF download ships Excel plus OSCAL-ready JSON versions.
What is the difference between Third-Party Risk Management (TPRM) and C-SCRM?
TPRM covers all third-party risk: financial, operational and cyber. C-SCRM narrows to cybersecurity in tech supply chains, software integrity and hardware.
What is the SCF's Supply Chain Risk Management (SCRM) domain?
The SCF SCRM domain covers vendor risk assessments, SBOM management, software supply chain security, and NIST SP 800-161 Rev. 1 alignment for C-SCRM programs.
What is supply chain due diligence?
Supply chain due diligence verifies supplier certifications, financial health, regulatory compliance and concentration risk before and during the relationship.
What is a vendor risk questionnaire?
A vendor risk questionnaire assesses third-party security practices. SIG and CSA CAIQ are common formats; validate answers with evidence for high-risk firms.
What supply chain security guidance does CISA provide?
CISA publishes supply chain security guidance covering ICT risk evaluation, software supply chain recommendations and sector-specific advice at cisa.gov.
How does SCF address Supply Chain Risk Management?
The SCF's SCRM domain maps to NIST SP 800-161, CMMC SR and ISO 27001 supplier controls, covering the C-SCRM lifecycle from governance to incident response.
What is supply chain transparency?
Supply chain transparency means visibility into supplier identities, data handling and risk flow, achieved through disclosure rules, SBOMs and supply maps.
What is fourth-party risk?
Fourth-party risk comes from your vendors' vendors. A sub-processor breach can hit you with no direct relationship, so sub-processor visibility is essential.
How does NIST CSF address Supply Chain Risk Management?
NIST CSF 2.0 elevated Supply Chain Risk Management by including C-SCRM in the Govern function and supply chain risk assessment in the Identify function.
What is a Software Bill of Materials (SBOM)?
An SBOM is a formal inventory of software components and dependencies, letting you quickly identify affected systems when a component vulnerability appears.
What are common supply chain attack vectors?
Supply chain attack vectors include malicious software updates, compromised hardware, stolen supplier credentials, counterfeit parts and social engineering.
How do I create an Authorized Supplier List?
An Authorized Supplier List is a controlled vendor registry. Build one by setting approval criteria, assessing vendors, documenting approvals and reviewing.
How does supply chain risk relate to CMMC compliance?
CMMC extends CUI protection through the supply chain. Primes must flow requirements down to subcontractors handling CUI. The SCF maps to CMMC's SR domain.
What is a supplier risk assessment?
A supplier risk assessment reviews a vendor's security controls, data access, financial stability and compliance. Depth should match supplier criticality.
What does NIST SP 800-161 cover?
NIST SP 800-161 Rev. 1 covers C-SCRM program setup, supplier risk assessments, software supply chain security and 800-53 overlays for supply chain risk.
What is Cyber Supply Chain Risk Management (C-SCRM)?
C-SCRM manages cybersecurity risk in supply chains: malicious code, compromised supplier access and third-party component flaws. NIST SP 800-161 guides it.
What is Supply Chain Risk Management (SCRM)?
SCRM identifies, assesses and controls risk from suppliers and vendors, including disruption, counterfeit parts, compromised software and concentration risk.
What is the SCF's mapping to ISO 27001:2022?
See how the SCF maps to ISO 27001:2022's 93 controls and 11 new requirements, streamlining certification preparation and cross-framework compliance work.
Is ISO 27001 required by law?
ISO 27001 is voluntary in most jurisdictions, but government contracts and enterprise buyers often make it functionally mandatory. See when it is required.
What is a corrective action under ISO 27001?
An ISO 27001 corrective action is a documented response to a nonconformity requiring root cause analysis, action to prevent recurrence and verified results.
What new controls were added in ISO 27001:2022?
ISO 27001:2022 added 11 new controls covering threat intelligence, cloud security, configuration management, data masking, leak prevention and secure coding.
How does SCF map to ISO 27001?
The SCF maps directly to ISO 27001:2022 Annex A, so you can build one unified control set that satisfies ISO 27001 and other frameworks without duplication.
Can small organizations achieve ISO 27001 certification?
ISO 27001 has no minimum size requirement. Small organizations can narrow ISMS scope to specific services and pick certification bodies that scale fees.
What is ISO 27002?
ISO 27002 is the companion guidance to ISO 27001, giving implementation detail for Annex A controls. It is a reference document, not a certifiable standard.
How do I select an ISO 27001 certification body?
Pick an ISO 27001 certification body on accreditation (ANAB/UKAS), industry experience, pricing and references. Switching bodies means a new full audit.
How does ISO 27001 relate to SOC 2?
ISO 27001 gives international ISMS recognition while SOC 2 satisfies US enterprise buyers. Many organizations pursue both given the large control overlap.
What are ISO 27001 surveillance audit requirements?
ISO 27001 requires annual surveillance audits after certification and full recertification every three years, plus internal audits between external ones.
What is the ISO 27001 risk assessment process?
ISO 27001 risk assessment identifies threats, vulnerabilities, likelihood and impact, then feeds a treatment plan that selects Annex A controls per risk.
What is a Statement of Applicability (SoA) in ISO 27001?
An ISO 27001 Statement of Applicability lists every Annex A control with applicability and justification. Exclusions must be risk-based, not convenience.
How long does ISO 27001 certification take?
ISO 27001 certification usually takes 6 to 18 months from initial scoping, followed by annual surveillance audits and full recertification every three years.
What are the ISO 27001 Annex A control themes?
ISO 27001:2022 Annex A organizes 93 controls into four themes: Organizational (37), People (8), Physical (14), and Technological (34).
How does ISO 27001:2022 differ from ISO 27001:2013?
ISO 27001:2022 restructured Annex A from 114 controls in 14 domains to 93 in 4 themes and added 11 controls covering cloud, threat intel and data masking.
What is an Information Security Management System (ISMS)?
An ISMS is a systematic framework for managing information security risk. ISO 27001 sets its requirements: scope, risk assessment, treatment and controls.
What is ISO 27001?
ISO/IEC 27001 is the international standard for information security management systems, covering how to establish, run and continually improve an ISMS.
What is the difference between SOC 1 and SOC 2?
SOC 1 covers internal control over financial reporting. SOC 2 covers security, availability, processing integrity, confidentiality and privacy. Compare both.
How much does a SOC 2 audit cost?
SOC 2 audit cost depends on organization size, audit firm, Type I vs Type II and the Trust Service Criteria in scope. See the drivers and how to cut prep.
What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment tests controls against the Trust Service Criteria before the formal audit, finding gaps and prioritizing remediation early.
How does SCF support SOC 2 compliance?
The SCF maps directly to the SOC 2 Trust Service Criteria, supplying control documentation for audit evidence while advancing ISO 27001 and NIST CSF work.
Do I need SOC 2 to sell to enterprise customers?
SOC 2 is not a legal requirement but is the de facto standard for B2B software. Enterprise buyers in finance, healthcare and tech routinely require Type II.
What is the SOC 2 Availability Trust Service Criteria?
The SOC 2 Availability criteria apply when you make uptime commitments, covering fault tolerance, backup and recovery, monitoring and disaster recovery.
How does SOC 2 relate to NIST CSF?
SOC 2 Trust Service Criteria and NIST CSF overlap significantly. SCF provides cross-framework mappings between SOC 2 TSC categories and NIST CSF subcategories.
How is SOC 2 audit scope determined?
SOC 2 scope comes from your service commitments and the systems delivering them. The system description captures infrastructure, software, people and data.
Who performs SOC 2 audits?
Only a licensed CPA firm can issue a SOC 2 attestation report. Readiness assessments can be run internally or by consultants, but the report needs a CPA.
What is a SOC 2 bridge letter?
A SOC 2 bridge letter confirms no material control changes since the report period ended, giving customers interim assurance while the next audit runs.
What SOC 2 controls cover system monitoring?
SOC 2 CC7 (System Operations) covers security event monitoring, log management, incident detection and response, and vulnerability management processes.
What does SOC 2 CC6 require?
SOC 2 CC6 requires least-privilege access, authentication, encryption in transit and at rest, physical access controls and prompt removal of stale access.
How long does a SOC 2 audit take?
SOC 2 Type I takes about 2-6 months. Type II takes 9-15 months due to the 6-month observation window. Readiness work adds 1-3 months before the audit.
What is the difference between SOC 2 Type I and Type II?
SOC 2 Type I assesses control design at a point in time. Type II assesses design and operating effectiveness over 6-12 months, which enterprises expect.
What are the SOC 2 Trust Service Criteria?
The SOC 2 Trust Service Criteria include mandatory Security (CC1-CC9) plus optional Availability, Processing Integrity, Confidentiality and Privacy sets.
What is SOC 2?
SOC 2 is an AICPA attestation framework that evaluates service organization controls against the Trust Service Criteria and is issued by a licensed CPA firm.
What is the SCF's approach to NY DFS 23 NYCRR Part 500 compliance?
See how the SCF maps controls to NY DFS Part 500: penetration testing, MFA, encryption, CISO accountability, Class A rules and 2023 amendment compliance.
What are the penalties for non-compliance with NY DFS 23 NYCRR Part 500?
NY DFS Part 500 non-compliance brings significant civil fines, individual officer accountability under the 2023 amendments and public enforcement actions.
What does NY DFS Part 500 require for privileged accounts?
NY DFS Part 500 requires MFA, annual access reviews, least privilege and activity monitoring for privileged accounts, plus PAWs for Class A companies.
What is the annual certification requirement under NY DFS Part 500?
NY DFS Part 500 requires annual CEO or CISO certification of compliance filed with DFS by April 15. The 2023 amendments created individual accountability.
What is the NY DFS Part 500 exemption threshold?
NY DFS Part 500 exemptions cover entities under 10 employees, $5M in revenue or $10M in assets. Even exempt entities must still file a notice of exemption.
How does SCF align with NY DFS Part 500?
The SCF maps directly to NY DFS Part 500 across governance, risk assessment, MFA, access control, penetration testing, incident response and third-party risk.
What are NY DFS Part 500 third-party vendor management requirements?
NY DFS Part 500 requires written third-party security policies, vendor assessments, cybersecurity contract clauses, breach notice rights and access reviews.
What is a Class A company under NY DFS Part 500?
Class A companies under NY DFS Part 500 have 2,000+ employees or $1B+ revenue and face enhanced rules including independent audits and stricter access control.
Does NY DFS Part 500 require Multi-Factor Authentication?
The 2023 NY DFS Part 500 amendments require MFA for all remote access and all privileged accounts, with limited CISO-documented exceptions permitted.
What is the 72-hour reporting rule under NY DFS Part 500?
NY DFS Part 500's 72-hour rule requires covered entities to notify DFS within 72 hours of determining a cybersecurity event materially harmed operations.
What are the NY DFS Part 500 incident reporting requirements?
NY DFS Part 500 requires 72-hour notice for material cybersecurity events and 24-hour notice for ransom payments. Third-party events also require reporting.
What is a covered entity under NY DFS Part 500?
A NY DFS Part 500 covered entity is any DFS-licensed person or organization. Class A firms face enhanced rules; smaller entities may qualify for exemptions.
What are the NY DFS Part 500 penetration testing requirements?
NY DFS Part 500 requires annual penetration testing by qualified testers. Class A companies face enhanced methodology rules; document results and remediation.
What is the CISO role under NY DFS Part 500?
NY DFS Part 500 requires a qualified CISO to oversee the cybersecurity program and report annually to the board. The role can be outsourced, accountability not.
What changed in the 2023 NY DFS Part 500 amendments?
The 2023 NY DFS Part 500 amendments added senior executive certification, mandatory MFA, 72-hour event notice, 24-hour ransom notice and Class A requirements.
Who must comply with NY DFS Part 500?
NY DFS Part 500 applies to DFS-licensed entities: banks, lenders, insurers, money transmitters and foreign banking organizations operating in New York.
What is NY DFS 23 NYCRR Part 500?
NY DFS Part 500 is New York's cybersecurity regulation for DFS-licensed financial institutions, first effective in 2017 and significantly amended in 2023.
What is the difference between CCPA and GDPR?
Compare CCPA/CPRA and GDPR: scope, thresholds, legal basis vs. opt-out, consumer rights, and penalty structures. Which privacy law applies to your organization?
What is the SCF's Privacy Management domain for CCPA/CPRA compliance?
See how the SCF Privacy Management domain covers CCPA/CPRA: consumer rights, data mapping, consent controls and the Sensitive Personal Information rules.
What are CPRA civil penalties?
CPRA civil penalties reach $2,500 per unintentional violation and $7,500 per intentional violation, with enhanced penalties for children's data violations.
What is the CPRA right to opt out?
CPRA lets consumers opt out of the sale or sharing of personal information. Businesses must honor opt-outs in 15 business days and wait 12 months to re-ask.
How does SCF map to CCPA/CPRA controls?
SCF's Privacy domain maps to CCPA/CPRA requirements covering data subject rights, data inventory, consent management, vendor agreements, and data retention.
What is ADMT and how does CPRA regulate it?
CPRA's ADMT rules cover AI and algorithmic decisions about consumers. Draft rules add an opt-out right and pre-deployment assessments; verify CPPA rules.
What is a CPRA privacy risk assessment?
CPRA requires privacy risk assessments before high-risk processing, weighing benefits against consumer privacy risk and documenting the safeguards in place.
What are CPRA cybersecurity audit requirements?
CPRA requires annual cybersecurity audits for businesses posing significant privacy risk. Final CPPA rules set scope and reporting, so verify current text.
What does CPRA require for Sensitive Personal Information?
CPRA's Sensitive Personal Information covers geolocation, health, biometric and financial data. Consumers can limit its use and businesses reply in 15 days.
What is a Data Subject Access Request (DSAR)?
A DSAR is a formal consumer privacy rights request. Under CCPA/CPRA businesses must answer verified DSARs within 45 days, with one 45-day extension allowed.
What consumer rights does CCPA/CPRA provide?
CCPA/CPRA give California consumers rights to know, delete, correct and opt out of the sale or sharing of personal data, plus limits on sensitive data use.
Who must comply with CCPA and CPRA?
CCPA/CPRA applies to for-profit businesses meeting revenue, data volume, or data-sale revenue thresholds, regardless of where the business is headquartered.
What is the California Privacy Rights Act (CPRA)?
The CPRA expanded the CCPA with Sensitive Personal Information protections, the CPPA, cybersecurity audit requirements and new consumer rights from 2023.
What is the California Consumer Privacy Act (CCPA)?
The CCPA gives California consumers rights to know, delete, and opt out of the sale of their personal information. Learn which businesses must comply.
When do FIPS 140-2 validations expire and what happens after September 2026?
FIPS 140-2 validations move to Historical status on September 21, 2026. Learn what that means for federal and commercial organizations and the next steps.
What is FIPS 140-3 and how does it replace FIPS 140-2?
FIPS 140-3 replaced FIPS 140-2 for cryptographic module validation, and FIPS 140-2 validations move to Historical status on September 21, 2026. See the impact.
What is the SCF's Quantum Security (QTS) domain?
The SCF Quantum Security (QTS) domain provides controls for post-quantum readiness, FIPS 203/204/205 alignment, algorithm agility and PQC migration planning.
Does FIPS 140-3 cover post-quantum algorithms?
NIST was incorporating PQC algorithms into FIPS 140-3 CMVP validation as of mid-2025. Monitor NIST announcements for current validated PQC module availability.
What is the Q-Day concept in quantum security?
Q-Day is the hypothetical date quantum computers break current public-key cryptography. NSA and CISA advise starting PQC migration now, not waiting for it.
What is FIPS 203?
FIPS 203 is the NIST post-quantum standard for ML-KEM (CRYSTALS-KYBER), a key encapsulation mechanism with three security parameter sets finalized in 2024.
How does the SCF address quantum security?
The SCF's Cryptographic Management domain covers algorithm selection, key management and crypto-agility, the control foundation for PQC migration planning.
What sectors face the greatest quantum security risk?
Government, financial services, healthcare and critical infrastructure face the greatest quantum risk from long-lived data exposed to harvest-now-decrypt.
How do I inventory my cryptographic assets?
A cryptographic asset inventory documents every use of cryptography - algorithms, key lengths, certificates and dependencies - as the basis for PQC migration.
What is ML-KEM (formerly CRYSTALS-KYBER)?
ML-KEM (formerly CRYSTALS-KYBER) is NIST's FIPS 203 post-quantum key encapsulation mechanism, replacing RSA and Diffie-Hellman for key establishment.
When might quantum computers break RSA?
Estimates range from 10 to 30+ years, but NSA and CISA advise starting PQC migration now because infrastructure migrations take years whatever the timeline.
What is crypto-agility?
Crypto-agility is designing systems that can swap cryptographic algorithms without major rework, which makes post-quantum migration far more manageable.
How do I start a Post-Quantum Cryptography migration?
Start PQC migration with a cryptographic inventory, then assess data sensitivity and build a prioritized roadmap beginning with long-lived sensitive data.
What is a harvest-now-decrypt-later attack?
Harvest-now-decrypt-later attacks capture encrypted data today to decrypt it later with quantum computers. Long-lived sensitive data is the most at risk.
What NIST Post-Quantum Cryptography standards have been finalized?
NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) as Post-Quantum Cryptography standards in August 2024.
Which cryptographic algorithms are vulnerable to quantum attacks?
RSA and ECC-based algorithms are most vulnerable to quantum attacks. Symmetric AES-256 and SHA-256 are more resilient. Learn how to prioritize your migration.
What is Post-Quantum Cryptography?
Post-Quantum Cryptography refers to algorithms designed to resist quantum computer attacks, replacing RSA and ECC with quantum-resistant alternatives.
How do I build an AI governance program from scratch?
A step-by-step guide to building an AI governance program: AI system inventory, NIST AI RMF risk assessment, policy, bias testing and ongoing monitoring.