Secure Controls Framework
Download The SCF

SCR-RMM: Risk Management Model

The Secure, Compliant & Resilient Risk Management Model (SCR-RMM) is a free, structured methodology to identify, assess, report and mitigate risk. Jointly developed by ComplianceForge and the SCF, the SCR-RMM breaks risk management down into seventeen (17) distinctive steps, from establishing risk management principles through implementing and documenting risk treatment.

Overview

What Is The SCR-RMM?

The Secure, Compliant & Resilient Risk Management Model (SCR-RMM) is a free, 17-step methodology to identify, assess, report and mitigate risk across the entire organization. It was developed jointly by ComplianceForge and the Secure Controls Framework (SCF).

The SCR-RMM ties risks and threats directly to an organization's controls and standardizes how risk is defined across the organization. Each assessment produces a documented finding for the management that owns the risk and decides how it is handled.

SCR Risk Management Model (SCR-RMM) product card showing ComplianceForge and SCF logos with Security Compliant Resilient branding and link to view example PDF

"Don't Shoot The Messenger" Protections

Cybersecurity and Information Technology (IT) departments generally do not own technology-related risks; Line of Business (LOB) management does. Quality risk management documentation can prove that reasonable steps were taken to identify, assess, report and mitigate risk, which keeps the responsibility with the management that owns the risk rather than the Chief Information Officer (CIO) or Chief Information Security Officer (CISO). If risk management discussions are not documented, risk management practices do not exist.

Audience

Who Is The SCR-RMM For?

The SCR-RMM is written for the cybersecurity and data privacy functions that run risk assessments and for the management that decides what to do with the results.

Cybersecurity And Data Privacy Teams

They assess controls, score the risk from each deficiency and report the findings to management.

Line Of Business Management

LOB management owns technology-related risk and chooses how each risk is treated.

Executive Leadership And The Board

Executive leadership sets the risk appetite, and the most serious risk decisions go to Executive Management or the Board of Directors.

Structure

How Is The SCR-RMM Organized?

The SCR-RMM opens with its core risk management vocabulary and a one-page diagram of all 17 steps. The steps follow, then five appendices of reference material, including the risk scoring formula and risk matrix.

StepNameActivity
1Identify Risk Management PrinciplesIdentify one or more risk management principles, such as National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, International Organization for Standardization (ISO) 31010, Committee of Sponsoring Organizations of the Treadway Commission (COSO) 2019 or Office of Management and Budget (OMB) A-123, as the basis for the organization's approach to risk management.
2Identify, Implement & Document Critical DependenciesEstablish the risk management dependencies (2A), such as the acceptable risk threshold, likelihood, impact and risk levels; the technology dependencies (2B), such as current inventories, network diagrams and Data Flow Diagrams (DFD); and the business dependencies (2C), such as a consistent data classification scheme and a Supply Chain Risk Management (SCRM) program.
3Formalize Risk Management PracticesDocument a formal Risk Management Program (RMP) that supports the organization's policies and standards and defines the who, what, why, when and how of its risk management practices.
4Establish A Risk CatalogDevelop a risk catalog of the possible risks that affect the organization, used to identify the risks associated with a control deficiency.
5Establish A Threat CatalogDevelop a catalog of natural threats (5A) and manmade threats (5B) that affect the execution of the organization's controls.
6Establish A Controls CatalogDevelop a catalog of controls that addresses the organization's statutory, regulatory and contractual obligations, ideally weighted, combining Minimum Compliance Requirements (MCR) and Discretionary Security Requirements (DSR).
7Define Capability Maturity Model (CMM) TargetsDefine the level of maturity expected of each control, using a capability maturity model such as the SCR-CMM as the benchmark.
8Define Assessment RigorSelect a level of rigor: Standard (8A, low assurance), Enhanced (8B, moderate assurance) or Comprehensive (8C, high assurance).
9Establish The Context For Assessing RisksDefine the operating environment in scope for the assessment, generally found in a System Security & Privacy Plan (SSPP), using the Unified Scoping Guide (USG) when no law, regulation or contract gives scoping instructions.
10Conformity Assessment (Controls Gap Assessment)Assess the in-scope controls against their Assessment Objectives (AOs) to determine whether each control is implemented and operating as intended.
11Control Assessment Methods & FindingsAssess controls by examining, interviewing and testing (11A), using a manual or automated methodology (11B), and record each finding as Satisfactory, Not Applicable, Compensating Control or Deficient (11C).
12Determine Risk ExposureFor each deficient control, rate Impact Effect (12A) and Occurrence Likelihood (12B) to find the inherent risk (12C), then account for control weighting, control maturity and mitigating factors to find the residual risk (12D).
13Prioritize & Document Identified DeficienciesPrioritize each deficiency as Emergency, Elevated or Standard, and document it in a risk register, Plan of Action & Milestones (POA&M), risk assessment report, SSPP or another method.
14Risk Determination: Report on Conformity (ROC)Report to management with one of four risk determinations: Strictly Conforms (14A), Conforms (14B), Significant Deficiency (14C) or Material Weakness (14D).
15Identify The Appropriate Management AudienceTake each risk decision to a level of management with the authority to make it, such as Line Management, Senior Management, Executive Management or the Board of Directors.
16Management Determines Risk TreatmentThe management that owns the business process or technology decides to reduce, avoid, transfer or accept the risk.
17Cybersecurity & Data Protection Practitioners Implement & Document Risk TreatmentImplement the chosen treatment and track each risk as Open (unacceptable risk), Open (acceptable risk) or Closed.
SCR-RMM example PDF preview showing the cyber risk management workflow with risk assessment matrices, threat mapping diagrams, control selection flowcharts, and risk scoring tables used in the Secure Controls Framework
Implementation

How Do Organizations Use The SCR-RMM?

The 17 steps fall into six phases, and Steps 8 to 17 repeat as continuous risk monitoring and assessments.

01

Set The Foundations

The organization picks its risk management principles, puts its risk management, technology and business dependencies in place, and documents them in a formal Risk Management Program (RMP).

Steps 1 to 3
02

Build The Catalogs

It establishes risk, threat and controls catalogs, then sets maturity targets for each control using the Secure, Compliant & Resilient Capability Maturity Model (SCR-CMM). The current risk and threat catalogs are in the SCF workbook.

Steps 4 to 7
03

Scope The Assessment

Each assessment starts with a level of rigor (Standard, Enhanced or Comprehensive) and a defined scope, because incorrect scoping leads to an inaccurate risk assessment.

Steps 8 and 9
04

Assess And Score The Controls

Each control is assessed against its Assessment Objectives and found Satisfactory, Not Applicable, Compensating Control or Deficient. Each deficiency is scored for inherent and residual risk, prioritized and documented.

Steps 10 to 13
05

Report And Decide

A Report on Conformity (ROC) gives one of four risk determinations: Strictly Conforms, Conforms, Significant Deficiency or Material Weakness. The appropriate level of management then decides to reduce, avoid, transfer or accept each risk.

Steps 14 to 16
06

Implement And Track

Practitioners implement the chosen treatment and track each risk as Open (unacceptable risk), Open (acceptable risk) or Closed.

Step 17

The full steps, scoring tables and reporting criteria are in the SCR-RMM.

Risk Hierarchy

Strategic, Operational & Tactical Risk Considerations

The SCR-RMM ties risk management to business planning at three levels: the risk appetite defines the risk tolerance, which sets the risk thresholds.

Strategic (Risk Appetite)

Executive leadership sets the risk appetite at the corporate level: the types and amount of risk the organization is willing to accept in its pursuit of value.

  • Mission & Vision
  • Strategy
  • Compliance Obligations
  • Risk Appetite

Operational (Risk Tolerance)

LOB management puts the risk tolerance into practice: the level of risk the organization is willing to assume to achieve a desired result.

  • LOB Objectives
  • Capability Maturity Targets
  • Resource Prioritization
  • Risk Tolerance

Tactical (Risk Thresholds)

Departments and teams assess operational risk against risk thresholds, the decision points that trigger management action and response escalation.

  • Department & Team Objectives
  • Processes & Technologies
  • Staffing & Supply Chain
  • Risk Thresholds
Catalogs

Risk And Threat Catalogs

The risk catalog answers what risk the organization is exposed to if a control fails. The threat catalog answers whether a control will function as expected if a threat materializes.

✓

Risk: A risk exists due to the absence of or a deficiency with a control.

✓

Threat: A threat affects the ability of a control to exist or operate properly.

✓

Natural Threat: A threat caused by environmental phenomena, such as floods or earthquakes.

✓

Manmade Threat: A threat caused by an element of human intent, negligence or error, or threat of violence.

Current Catalogs

The catalog tables printed in the SCR-RMM are out of date. The current catalogs are the Risk Catalog and Threat Catalog tabs in the SCF workbook, where the SCR-RMM's risk numbers appear in the Old Risk # column.

Risk Determinations

Four Risk Determinations

Each assessment ends in one of four risk determinations, which normalize how conformity is described.

Strictly Conforms

A positive outcome. Every assessed control is met and operational, or the assessor has validated it as Not Applicable (N/A) or covered by a compensating control.

Conforms

A positive outcome. At least 80% of the assessed controls pass on that basis, and no deficiency is material.

Significant Deficiency

A negative outcome. At least 70% but less than 80% pass because of a systemic problem, and no deficiency is material.

Material Weakness

A negative outcome. One or more material controls are deficient and/or less than 70% pass, and the program needs drastic changes to perform its stated mission.

Material Controls

A material control is so fundamental that it cannot have compensating controls, and its absence or failure could have a material impact. A deficient material control means a Material Weakness.

SCF Ecosystem

SCR-RMM Works With The SCF Ecosystem

The SCR-RMM draws on other free SCF content for controls, maturity targets and scoping.

SCF Controls

Step 6 builds the controls catalog. The SCF's 1,500+ controls carry weighting values from 1 to 10, and the SCF workbook holds the Assessment Objectives (AOs) for Step 10 and the current catalogs.

SCR-CMM

Step 7 uses the SCR-CMM's control-level maturity criteria as the benchmark to evaluate controls. Control maturity is also a factor in residual risk (Step 12D).

Unified Scoping Guide (USG)

Step 9 uses the USG as the basis for scoping sensitive and regulated data when no law, regulation or contract gives scoping instructions.