The Operational Companion to the SCRMS
The SCRMS defines what a secure, compliant and resilient program looks like. The SCRMS-PIG defines the order in which to build it. It provides a sequenced, dependency-aware roadmap that supports the entity's mission, avoids rework caused by implementing capabilities before their dependencies exist, aligns funding and resources with business risk, and produces audit-ready evidence as a byproduct.
Entities rarely fail because they lack controls. Failures more often occur because leadership cannot prove reasonable prioritization, or cannot show evidence of oversight after the fact. The SCRMS-PIG addresses both gaps by aligning capabilities with Enterprise Risk Management (ERM), separating execution from oversight, and producing defensible evidence of due diligence and due care.

The guide is equally applicable whether an entity is establishing a program from scratch or rationalizing overlapping compliance obligations across frameworks such as NIST CSF 2.0, PCI DSS, ISO 27001, ISO 42001, the HIPAA Security Rule and SOC 2.
Built for Accountability, Not Checklists
The SCRMS is built to model material risk and material control failure. It was purpose-built for real-world accountability rather than checklist compliance, with the expectation that those developing, implementing and governing capabilities do so in a manner that would withstand scrutiny from an external auditor, a regulator or a prosecuting attorney.
What Executives and Board Members Get Out of It
By adopting the SCRMS and the SCRMS-PIG, an entity's leadership gains clear visibility into risk posture, documented oversight and accountability, evidence of reasonable decision-making, confidence in legally defensible evidence of conformity, and a shared language between business, risk, legal and technical stakeholders.
The Claim Leadership Can Credibly Make
We understand our risks, we prioritize them rationally and we continuously adapt our capabilities as conditions change.
Making that claim credible depends on a clean split between doing the work and governing the work. The SCRMS intentionally distinguishes execution from oversight, which enables leadership to exercise due care without assuming operational or technical responsibilities.
Management: Execution
Responsible for designing, implementing and operating security, compliance and resilience capabilities. Management owns the build, the day-to-day operation of controls, and the production of evidence that controls exist and work as intended.
Executives & the Board: Oversight
Responsible for oversight, risk acceptance and strategic direction. Leadership challenges assumptions, confirms priorities align with business risk, and ensures unresolved risks are consciously accepted rather than quietly inherited.
Sequencing Beats Coverage
Security, compliance and resilience capability failures are rarely caused by missing controls. They are caused by misaligned sequencing, constrained resources and unmanaged dependencies. The SCRMS-PIG exists to make that sequencing explicit.
The Critical Resource Enablement Path (CREP) is a resource-flow governance mechanism representing the sequence in which constrained resources must be enabled to prevent bottlenecks that undermine outcomes. CREP ensures foundational capabilities are established before dependent capabilities are introduced. Errors with People, Processes, Technologies, Data or Facilities early in implementation have cascading effects later, so the SCRMS-PIG provides a model for prioritizing effort under real constraints such as budget limits, supply chain issues and staffing shortages.
Underneath CREP sits the Theory of Constraints (TOC). Capabilities are not optimized by maximizing individual control performance, but by identifying and managing the single most limiting constraint that prevents the entity from achieving reasonable, defensible outcomes. Applying TOC through CREP lets an entity demonstrate that resource allocation decisions were made rationally, based on identified constraints and documented dependencies.
What a Constraint Actually Looks Like
An entity deploys a Security Incident Event Manager (SIEM) but lacks trained analysts and defined escalation procedures, so incident response effectiveness stays constrained by staffing and process maturity despite the tooling investment. Another implements Secure Baseline Configurations (SBC), but an immature change management process produces frequent unauthorized changes that negate the benefit of hardened baselines. In both cases the missing capability was never the control itself.
Due Diligence Builds It. Due Care Governs It.
The thirty (30) steps divide into two phases that map to the two constructs the SCRMS is built on. The first phase produces capability and evidence. The second phase proves leadership is governing what was built.
Steps 1 to 26: Due Diligence
Intentionally sequenced to establish context, address dependencies and implement foundational capabilities before advanced ones. These steps answer whether the entity has taken reasonable steps to build and operate secure, compliant and resilient capabilities, and they generate the bulk of an entity's defensible evidence.
Steps 27 to 30: Due Care
Designed for executive and board-level engagement, covering governance oversight, recurring risk management, capability testing and strategic evolution. These steps answer whether leadership is actively governing and adapting capabilities as risks and conditions change.
Thirty Steps, In Dependency Order
The table below lists all thirty (30) steps in sequence. Steps 1 through 26 are due diligence activities and are ordered so that foundational capabilities exist before dependent ones are introduced. Steps 27 through 30 are due care activities aimed at executive and board-level engagement. Steps 8 through 26 each produce Plan of Action & Milestones (POA&M) entries for identified deficiencies.
Five Lenses for Control Applicability
Appendix A of the SCRMS-PIG identifies PPTDF applicability at the control level, so implementers can see what each control actually acts upon. This matters for sequencing: a control that depends on people is constrained by staffing, while one that depends on technology is constrained by tooling and budget.
Proving Conformity to Stakeholders
Working through the thirty steps produces a significant volume of defensible evidence as a natural byproduct. Demonstrating that evidence to stakeholders is where the Secure Controls Framework Conformity Assessment Program (SCF CAP) comes in, providing an entity-level conformity assessment built on tailored controls that address the specific obligations an Organization Seeking Assessment (OSA) must comply with.
Audit readiness, under this model, is not a separate workstream. It is a byproduct of defensible governance.
The SCRMS-PIG sequences the work. For the underlying system it implements, including the nine principles, control set determination and the thirty-four domains of due diligence, see the SCRMS itself.
.png)
%20(white).png)