Secure Controls Framework
Download The SCF

SCRMS-PIG: Prioritized Implementation Guide

The SCRMS Prioritized Implementation Guide (SCRMS-PIG) is the operational companion to the SCRMS. It provides a sequenced, dependency-aware roadmap that breaks SCRMS implementation into thirty (30) major steps, twenty-six (26) focused on due diligence and four (4) focused on due care, so capabilities are built in an order that avoids rework and cascading failures.

30
Implementation Steps
26
Due Diligence Steps
4
Due Care Steps
FREE
To Download
About SCRMS-PIG

The Operational Companion to the SCRMS

The SCRMS defines what a secure, compliant and resilient program looks like. The SCRMS-PIG defines the order in which to build it. It provides a sequenced, dependency-aware roadmap that supports the entity's mission, avoids rework caused by implementing capabilities before their dependencies exist, aligns funding and resources with business risk, and produces audit-ready evidence as a byproduct.

Entities rarely fail because they lack controls. Failures more often occur because leadership cannot prove reasonable prioritization, or cannot show evidence of oversight after the fact. The SCRMS-PIG addresses both gaps by aligning capabilities with Enterprise Risk Management (ERM), separating execution from oversight, and producing defensible evidence of due diligence and due care.

SCRMS product card showing the Security Compliance and Resilience Management System by SCF with click to view example PDF link

The guide is equally applicable whether an entity is establishing a program from scratch or rationalizing overlapping compliance obligations across frameworks such as NIST CSF 2.0, PCI DSS, ISO 27001, ISO 42001, the HIPAA Security Rule and SOC 2.

Built for Accountability, Not Checklists

The SCRMS is built to model material risk and material control failure. It was purpose-built for real-world accountability rather than checklist compliance, with the expectation that those developing, implementing and governing capabilities do so in a manner that would withstand scrutiny from an external auditor, a regulator or a prosecuting attorney.

Executive Value

What Executives and Board Members Get Out of It

By adopting the SCRMS and the SCRMS-PIG, an entity's leadership gains clear visibility into risk posture, documented oversight and accountability, evidence of reasonable decision-making, confidence in legally defensible evidence of conformity, and a shared language between business, risk, legal and technical stakeholders.

The Claim Leadership Can Credibly Make

We understand our risks, we prioritize them rationally and we continuously adapt our capabilities as conditions change.

Making that claim credible depends on a clean split between doing the work and governing the work. The SCRMS intentionally distinguishes execution from oversight, which enables leadership to exercise due care without assuming operational or technical responsibilities.

Management: Execution

Responsible for designing, implementing and operating security, compliance and resilience capabilities. Management owns the build, the day-to-day operation of controls, and the production of evidence that controls exist and work as intended.

Executives & the Board: Oversight

Responsible for oversight, risk acceptance and strategic direction. Leadership challenges assumptions, confirms priorities align with business risk, and ensures unresolved risks are consciously accepted rather than quietly inherited.

Critical Resource Enablement Path

Sequencing Beats Coverage

Security, compliance and resilience capability failures are rarely caused by missing controls. They are caused by misaligned sequencing, constrained resources and unmanaged dependencies. The SCRMS-PIG exists to make that sequencing explicit.

The Critical Resource Enablement Path (CREP) is a resource-flow governance mechanism representing the sequence in which constrained resources must be enabled to prevent bottlenecks that undermine outcomes. CREP ensures foundational capabilities are established before dependent capabilities are introduced. Errors with People, Processes, Technologies, Data or Facilities early in implementation have cascading effects later, so the SCRMS-PIG provides a model for prioritizing effort under real constraints such as budget limits, supply chain issues and staffing shortages.

Underneath CREP sits the Theory of Constraints (TOC). Capabilities are not optimized by maximizing individual control performance, but by identifying and managing the single most limiting constraint that prevents the entity from achieving reasonable, defensible outcomes. Applying TOC through CREP lets an entity demonstrate that resource allocation decisions were made rationally, based on identified constraints and documented dependencies.

What a Constraint Actually Looks Like

An entity deploys a Security Incident Event Manager (SIEM) but lacks trained analysts and defined escalation procedures, so incident response effectiveness stays constrained by staffing and process maturity despite the tooling investment. Another implements Secure Baseline Configurations (SBC), but an immature change management process produces frequent unauthorized changes that negate the benefit of hardened baselines. In both cases the missing capability was never the control itself.

Two Phases

Due Diligence Builds It. Due Care Governs It.

The thirty (30) steps divide into two phases that map to the two constructs the SCRMS is built on. The first phase produces capability and evidence. The second phase proves leadership is governing what was built.

Steps 1 to 26: Due Diligence

Intentionally sequenced to establish context, address dependencies and implement foundational capabilities before advanced ones. These steps answer whether the entity has taken reasonable steps to build and operate secure, compliant and resilient capabilities, and they generate the bulk of an entity's defensible evidence.

Steps 27 to 30: Due Care

Designed for executive and board-level engagement, covering governance oversight, recurring risk management, capability testing and strategic evolution. These steps answer whether leadership is actively governing and adapting capabilities as risks and conditions change.

Implementation Sequence

Thirty Steps, In Dependency Order

The table below lists all thirty (30) steps in sequence. Steps 1 through 26 are due diligence activities and are ordered so that foundational capabilities exist before dependent ones are introduced. Steps 27 through 30 are due care activities aimed at executive and board-level engagement. Steps 8 through 26 each produce Plan of Action & Milestones (POA&M) entries for identified deficiencies.

#
Step
Focus
1
Establish Context For SCR Operations
Define the entity's mission, establish the Security, Compliance & Resilience Program (SCRP) with enforcement and resourcing authority, define Minimum Compliance Requirements (MCR) and identify applicable obligations.
2
Implement Centralized Governance Practices
From a centralized authority, develop and maintain policies and standards based on the Living Control Set, manage exception requests, assign control ownership and have stakeholders build Standardized Operating Procedures (SOP).
3
Align Risk Management Practices Across The Entity
Implement an entity-wide Risk Management Program tied into Enterprise Risk Management (ERM), define risk appetite, threshold and tolerance criteria, and define materiality for the entity.
4
Gain Clarity On The Entity's PPTDF
Build and maintain inventories for TAASD, external and cloud service providers and sensitive data, create network and data flow diagrams, and identify critical assets.
5
Resource The SCRP
Develop a resource plan covering business plan, budget and prioritized roadmap between the CISO and the PMO, then prioritize stakeholder objectives against it.
6
Establish Criteria To Be Secure, Compliant & Resilient
Define secure engineering principles, govern requirements across the System Development Lifecycle (SDLC), implement capabilities by default and by design, and plan for capacity and performance.
7
Establish Capabilities To Secure The Supply Chain
Develop a Cybersecurity Supply Chain Risk Management (C-SCRM) Plan, operationalize it through acquisition strategies and contract tools, enforce flow-down requirements and build a RASCI matrix.
8
Cybersecurity Operations
Empower cybersecurity and data protection personnel to enforce secure, compliant and resilient practices.
9
Human Resources (HR) Practices
Work with Human Resources to ensure personnel security requirements are integrated into HR operations.
10
Data Classification & Handling
Define and implement processes to securely handle data wherever it is stored, processed or transmitted, limiting logical and physical access to sensitive and regulated data.
11
Network Security
Develop and implement a segmented network architecture and industry-recognized secure practices for network security.
12
Change Management
Develop and implement change control processes, including a Change Control Board (CCB).
13
Incident Response Operations
Develop and implement incident response capabilities to detect, respond to and recover from incidents.
14
Situational Awareness Through Continuous Monitoring
Develop situational awareness capabilities through threat intelligence and log collection and analysis, such as a SIEM.
15
Secure Baseline Configurations (SBC)
Develop hardening standards for all technology platforms and enforce secure configurations across directory services and endpoint management tooling.
16
Identity & Access Management (IAM)
Develop IAM capabilities that address least privilege and Role-Based Access Control (RBAC).
17
IT Asset Management (ITAM)
Implement IT Asset Management practices, including Endpoint Device Management (EDM).
18
Embedded Technologies
Implement embedded technology governance practices for Operational Technology (OT) and Internet of Things (IoT) assets.
19
Proactive Maintenance
Develop and implement proactive maintenance practices.
20
Attack Surface Management (ASM)
Develop and implement Attack Surface Management practices.
21
Artificial Intelligence Governance (AIG)
Develop and implement Artificial Intelligence & Autonomous Technologies (AAT) governance practices.
22
Continuity of Operations Plan (COOP)
Develop and implement Business Continuity & Disaster Recovery (BC/DR) capabilities.
23
Data Privacy Program
Develop and implement a data privacy program.
24
Physical & Environmental Security
Develop and implement physical and environmental security capabilities.
25
Security-Minded Workforce
Develop a security, compliance and resilience-minded workforce through training and awareness.
26
Threat Intelligence
Develop and implement a Threat Intelligence Program (TIP).
27
Governance Oversight
Due care. Provide oversight of SCRP controls, deficiencies and remediation. The board should expect conformity assessment results and the status of open POA&M items, and should treat everything is green with no documented exceptions as a red flag.
28
Risk Management
Due care. Manage changes affecting security, compliance and resilience, including the supply chain. The board should expect an updated risk register, risk acceptance decisions, supply chain risk summaries and time-to-remediate trends.
29
Capability Testing
Due care. Test processes to validate assumptions, detect false confidence and prove resilience under stress. Testing that produces no findings is itself a red flag.
30
Evolving Capabilities
Due care. Report SCRP status to a governing body and redefine what reasonable means as conditions change, through quarterly business reviews, event-driven reviews and annual business planning.
PPTDF Applicability

Five Lenses for Control Applicability

Appendix A of the SCRMS-PIG identifies PPTDF applicability at the control level, so implementers can see what each control actually acts upon. This matters for sequencing: a control that depends on people is constrained by staffing, while one that depends on technology is constrained by tooling and budget.

#
Component
Control Directly Applies To
1
People
Humans, such as training, background checks and non-disclosure agreements.
2
Processes
Administrative work performed, such as processes, procedures and administrative documentation.
3
Technologies
Systems, applications and services, such as secure baseline configurations and patching.
4
Data
Data protection, such as encrypting sensitive and regulated data and applying metatags.
5
Facilities
Infrastructure assets, such as physical access, HVAC systems and visitor control.
Demonstrating Assurance

Proving Conformity to Stakeholders

Working through the thirty steps produces a significant volume of defensible evidence as a natural byproduct. Demonstrating that evidence to stakeholders is where the Secure Controls Framework Conformity Assessment Program (SCF CAP) comes in, providing an entity-level conformity assessment built on tailored controls that address the specific obligations an Organization Seeking Assessment (OSA) must comply with.

Audit readiness, under this model, is not a separate workstream. It is a byproduct of defensible governance.

The SCRMS-PIG sequences the work. For the underlying system it implements, including the nine principles, control set determination and the thirty-four domains of due diligence, see the SCRMS itself.