What Is The SCR-RMM?
The Secure, Compliant & Resilient Risk Management Model (SCR-RMM) is a free, 17-step methodology to identify, assess, report and mitigate risk across the entire organization. It was developed jointly by ComplianceForge and the Secure Controls Framework (SCF).
The SCR-RMM ties risks and threats directly to an organization's controls and standardizes how risk is defined across the organization. Each assessment produces a documented finding for the management that owns the risk and decides how it is handled.
"Don't Shoot The Messenger" Protections
Cybersecurity and Information Technology (IT) departments generally do not own technology-related risks; Line of Business (LOB) management does. Quality risk management documentation can prove that reasonable steps were taken to identify, assess, report and mitigate risk, which keeps the responsibility with the management that owns the risk rather than the Chief Information Officer (CIO) or Chief Information Security Officer (CISO). If risk management discussions are not documented, risk management practices do not exist.
Who Is The SCR-RMM For?
The SCR-RMM is written for the cybersecurity and data privacy functions that run risk assessments and for the management that decides what to do with the results.
Cybersecurity And Data Privacy Teams
They assess controls, score the risk from each deficiency and report the findings to management.
Line Of Business Management
LOB management owns technology-related risk and chooses how each risk is treated.
Executive Leadership And The Board
Executive leadership sets the risk appetite, and the most serious risk decisions go to Executive Management or the Board of Directors.
How Do Organizations Use The SCR-RMM?
The 17 steps fall into six phases, and Steps 8 to 17 repeat as continuous risk monitoring and assessments.
Set The Foundations
The organization picks its risk management principles, puts its risk management, technology and business dependencies in place, and documents them in a formal Risk Management Program (RMP).
Build The Catalogs
It establishes risk, threat and controls catalogs, then sets maturity targets for each control using the Secure, Compliant & Resilient Capability Maturity Model (SCR-CMM). The current risk and threat catalogs are in the SCF workbook.
Scope The Assessment
Each assessment starts with a level of rigor (Standard, Enhanced or Comprehensive) and a defined scope, because incorrect scoping leads to an inaccurate risk assessment.
Assess And Score The Controls
Each control is assessed against its Assessment Objectives and found Satisfactory, Not Applicable, Compensating Control or Deficient. Each deficiency is scored for inherent and residual risk, prioritized and documented.
Report And Decide
A Report on Conformity (ROC) gives one of four risk determinations: Strictly Conforms, Conforms, Significant Deficiency or Material Weakness. The appropriate level of management then decides to reduce, avoid, transfer or accept each risk.
Implement And Track
Practitioners implement the chosen treatment and track each risk as Open (unacceptable risk), Open (acceptable risk) or Closed.
The full steps, scoring tables and reporting criteria are in the SCR-RMM.
Strategic, Operational & Tactical Risk Considerations
The SCR-RMM ties risk management to business planning at three levels: the risk appetite defines the risk tolerance, which sets the risk thresholds.
Strategic (Risk Appetite)
Executive leadership sets the risk appetite at the corporate level: the types and amount of risk the organization is willing to accept in its pursuit of value.
- Mission & Vision
- Strategy
- Compliance Obligations
- Risk Appetite
Operational (Risk Tolerance)
LOB management puts the risk tolerance into practice: the level of risk the organization is willing to assume to achieve a desired result.
- LOB Objectives
- Capability Maturity Targets
- Resource Prioritization
- Risk Tolerance
Tactical (Risk Thresholds)
Departments and teams assess operational risk against risk thresholds, the decision points that trigger management action and response escalation.
- Department & Team Objectives
- Processes & Technologies
- Staffing & Supply Chain
- Risk Thresholds
Risk And Threat Catalogs
The risk catalog answers what risk the organization is exposed to if a control fails. The threat catalog answers whether a control will function as expected if a threat materializes.
Risk: A risk exists due to the absence of or a deficiency with a control.
Threat: A threat affects the ability of a control to exist or operate properly.
Natural Threat: A threat caused by environmental phenomena, such as floods or earthquakes.
Manmade Threat: A threat caused by an element of human intent, negligence or error, or threat of violence.
Current Catalogs
The catalog tables printed in the SCR-RMM are out of date. The current catalogs are the Risk Catalog and Threat Catalog tabs in the SCF workbook, where the SCR-RMM's risk numbers appear in the Old Risk # column.
Four Risk Determinations
Each assessment ends in one of four risk determinations, which normalize how conformity is described.
Strictly Conforms
A positive outcome. Every assessed control is met and operational, or the assessor has validated it as Not Applicable (N/A) or covered by a compensating control.
Conforms
A positive outcome. At least 80% of the assessed controls pass on that basis, and no deficiency is material.
Significant Deficiency
A negative outcome. At least 70% but less than 80% pass because of a systemic problem, and no deficiency is material.
Material Weakness
A negative outcome. One or more material controls are deficient and/or less than 70% pass, and the program needs drastic changes to perform its stated mission.
Material Controls
A material control is so fundamental that it cannot have compensating controls, and its absence or failure could have a material impact. A deficient material control means a Material Weakness.
SCR-RMM Works With The SCF Ecosystem
The SCR-RMM draws on other free SCF content for controls, maturity targets and scoping.
SCF Controls
Step 6 builds the controls catalog. The SCF's 1,500+ controls carry weighting values from 1 to 10, and the SCF workbook holds the Assessment Objectives (AOs) for Step 10 and the current catalogs.
SCR-CMM
Step 7 uses the SCR-CMM's control-level maturity criteria as the benchmark to evaluate controls. Control maturity is also a factor in residual risk (Step 12D).
Unified Scoping Guide (USG)
Step 9 uses the USG as the basis for scoping sensitive and regulated data when no law, regulation or contract gives scoping instructions.
.png)


%20(white).png)