Secure Controls Framework
Download The SCF

SCR-CMM: Capability Maturity Model. Measure & Advance Your Cybersecurity Program

The Secure, Compliant & Resilient Capability Maturity Model (SCR-CMM) provides a six-level (L0 to L5) maturity scoring system for every control in the Secure Controls Framework® (SCF), enabling organizations to objectively assess where they are today, define where they need to be, and measure progress over time. Built on the SSE-CMM v2.0 structure.

Overview

What Is The SCR-CMM?

The Secure, Compliant & Resilient Capability Maturity Model (SCR-CMM) is the maturity model of the Secure Controls Framework (SCF). It defines six levels, from Level 0 (Not Performed) to Level 5 (Continuously Improving), and the SCF workbook includes maturity criteria for every SCF control.

The SCR-CMM "is meant to solve the problem of objectivity in both establishing and evaluating cybersecurity and data privacy controls." It is free to use, and it adds control-level criteria to the high-level structure of the Systems Security Engineering Capability Maturity Model v2.0 (SSE-CMM).

Secure Controls Framework (SCF) Capability Maturity Model (SCR-CMM)

Not Just Another Maturity Model

Rather than reinvent the wheel, the SCF chose the SSE-CMM as the best model to demonstrate varying levels of maturity for people, processes and technology at a control level. The SSE-CMM is community-owned, free to use and also referenced by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) as ISO/IEC 21827:2008.

Audience

Who Is The SCR-CMM For?

The SCR-CMM is written for cybersecurity and data privacy practitioners. Its four objectives, each with a defined use case, show who uses it.

Use Case 1

Objective Criteria To Build A Cybersecurity Program

Gives Chief Information Security Officers (CISOs), Chief Information Officers (CIOs) and Chief Privacy Officers (CPOs) objective criteria for setting program expectations. Maturity goals define what right looks like, so expectations do not become moving targets.

Use Case 2

Assist Project Teams To Plan & Budget

Gives project teams objective criteria so that secure, compliant and resilient practices are planned and budgeted for before go-live.

Use Case 3

Evaluate External Service Provider Practices

Gives organizations objective criteria to evaluate External Service Providers (ESPs), which are commonly considered the soft underbelly of a security program.

Use Case 4

Due Diligence In Mergers, Acquisitions & Divestitures

Supports Mergers, Acquisitions & Divestitures (MA&D) due diligence. Deficiencies found in a maturity-based gap assessment can be costed to adjust valuations.

Structure

How Is The SCR-CMM Organized?

The SCR-CMM has an Executive Summary, the SCR-CMM Overview, the Defined Maturity Levels, a section on choosing a maturity "sweet spot" and four use cases. Each level builds on the one before it: Levels 0 and 1 are generally considered negligent, and Levels 2 to 5 are generally considered audit ready.

LevelThe guide's definitionWhat it generally means
Level 0: Not Performed"non-existent practices"The control is not performed. Generally considered negligent.
Level 1: Performed Informally"ad hoc practices"Performed, but without consistency and formality. Generally considered negligent.
Level 2: Planned & Tracked"requirements-driven" practicesTailored to specific compliance obligations and applied in some places, not across the enterprise. Generally considered "audit ready."
Level 3: Well Defined"enterprise-wide standardization"Standardized across the organization. Security-focused, with compliance as a "natural byproduct." Generally considered "audit ready."
Level 4: Quantitatively Controlled"metrics-driven practices"Level 3, plus detailed metrics that enable objective governance oversight. Generally considered "audit ready."
Level 5: Continuously Improving"world-class practices"Level 4, plus a capability to continuously improve the process. Artificial Intelligence (AI) and Machine Learning (ML) fit here, but are not required. Generally considered "audit ready."
Implementation

How Do Organizations Use The SCR-CMM?

The SCR-CMM has no numbered steps; organizations generally apply it in five phases.

01

Scope The Applicable Controls

Maturity targets apply to controls an organization actually needs. The SCF is first pared down to the controls that apply, based on priorities, resourcing and statutory, regulatory and contractual obligations.

Use Cases #1 to #3
02

Choose A Target Range

For most organizations, the sweet spot for maturity targets is between Level 2 and Level 4. The negligence threshold sits between Level 1 and Level 2, and noticeable risk reductions are harder to attain above Level 3.

Defined Maturity Levels
Sweet Spot
03

Set And Assign Targets

Technologists and business stakeholders set a target for each SCF domain, then for each control in those domains. Control targets are assigned to managers and Individual Contributors (ICs), and progress is ideally reviewed every quarter.

Use Case #1
04

Assess Current Maturity

Each control's current level is judged against its criteria, which describe what would reasonably exist at each level rather than serving as a checklist. Consciously designating a higher level than is justified should be considered fraud.

SCR-CMM Overview
05

Extend To Projects, ESPs And MA&D

Projects ideally inherit the organization's targets, usually limited to Level 2 to Level 3 for planning. ESPs answer from Level 0 to Level 5 instead of yes or no, and the same maturity-based approach supports MA&D due diligence.

Use Cases #2 to #4

The level definitions, sweet spot considerations and all four use cases are covered in full in the SCR-CMM.

Maturity Levels

What Each Level Looks Like In Practice

Each level is built upon its predecessor. The SCR-CMM also notes what each level often looks like in smaller and larger organizations.

Capability Maturity Model (CMM) levels depicted as ascending steps from 0 to 5, showing progression from Non-Existent Practices at CMM 0 to World-Class Practices at CMM 5.

Level 0

Not Performed

Smaller organizations often have only break/fix Information Technology (IT) support, while larger ones have IT or cybersecurity staff but governance is functionally non-existent.

Level 1

Performed Informally

IT support or staff exist, but the support contract is limited in scope or management does not focus time or resources on the control.

Level 2

Planned & Tracked

IT staff have clear compliance requirements; a dedicated cybersecurity role is unlikely in smaller organizations and likely in larger ones.

Level 3

Well Defined

A very competent leader, such as a security manager or a CISO, has the authority to direct resources to enact secure practices across the organization.

Level 4

Quantitatively Controlled

Unrealistic for smaller organizations; in larger ones, detailed metrics keep business stakeholders aware of the program's status, for example through quarterly business reviews.

Level 5

Continuously Improving

Unrealistic for small and medium-sized organizations; large ones have an industry-leading business model and invest heavily in Artificial Intelligence and Machine Learning for near real-time improvements.

Internal vs. External Maturity

Levels 0 to 3 are internal maturity levels, involving almost entirely IT, cybersecurity and data privacy. Levels 4 and 5 are external, with true business stakeholder involvement in oversight and process improvement.

Assurance

Maturity (Governance) Is Not Assurance (Security)

Higher maturity and higher assurance are not mutually inclusive. Maturity measures the governance activities around a control, not the strength and depth of the control. Increased rigor in control testing is what leads to increased assurance.

The SCR-CMM recognizes three levels of rigor to assess a control.

✓

Standard Rigor (Minimum Assurance): Determines whether the applicable controls are implemented and free of obvious errors.

✓

Enhanced Rigor (Moderate Assurance): Also provides increased grounds for confidence that the controls are implemented correctly and operating as intended.

✓

Comprehensive Rigor (High Assurance): Also provides further increased grounds for confidence that the controls operate as intended on an ongoing and consistent basis, with support for continuous improvement.

Assessors and auditors use three assessment methods to verify that an organization meets the intent of its applicable controls: examine, interview and test.

SCF Ecosystem

The SCR-CMM Works With The SCRMS And The SCF

The SCR-CMM draws on other free SCF content.

SCRMS

Defining target maturity is Principle 3 (Define Maturity Expectations) of the Secure, Compliant & Resilient Management System (SCRMS), which helps establish the prerequisites for setting targets.

SCF Workbook

The SCF workbook holds the maturity criteria for every SCF control, one column per level, along with the SCF domains and the SCF CORE MA&D control set.