Secure Controls Framework
Download The SCF

The SCF Is The Common Controls Framework®

The Secure Controls Framework®  (SCF) is the authoritative, comprehensive Common Controls Framework®  for cybersecurity and data privacy. The SCF maps major cybersecurity and data privacy law, regulation and framework requirements to a single, unified set of controls. This normalization eliminaties the expensive duplication of managing siloed frameworks.

The concept of a "common controls framework" is a unified security, compliance and resilience architecture that maps multiple laws, regulations, and industry standards to a single, authoritative control set. Instead of maintaining separate programs for NIST 800-171, ISO 27001, PCI DSS, HIPAA, and CMMC, an organization can implement a singe framework that satisfies all of them simultaneously. This concept eliminates audit fatigue, reduces duplicative documentation, and creates a defensible compliance posture that scales as new requirements emerge. It is, in short, the intelligent approach to enterprise cybersecurity governance.

Through years of rigorous development, continuous maintenance and broad industry adoption, the SCF has become the Common Controls Framework® (CCF). The SCF makes compliance a natural byproduct of secure and resilient practices and is the world's most comprehensive security, compliance and resilience metaframework. With 1,500+ controls across 34 domains and mappings to 200+ laws, regulations, and frameworks, the SCF is the common controls framework for building secure, compliant, and resilient capabilities.

The Common Controls Framework

One Common Controls Framework To Rule Them All

The Secure Controls Framework® (SCF) is an innovative solution designed to streamline enterprise compliance by integrating security, compliance, and resilience into a single, cohesive metaframework. This approach addresses the costly challenge of managing separate, isolated programs for each legal and regulatory requirement. By unifying these elements, the SCF simplifies compliance efforts, reduces redundancy, and enhances organizational efficiency.

Not familiar with the SCF? A great place to start is with downloading the START HERE GUIDE to gain a solid understanding of what the SCF is and how to use it. The SCF focuses on internal controls, which are security, compliance and resilience-related policies, standards, procedures, technologies, and processes designed to provide reasonable assurance that business objectives will be achieved and undesired events will be prevented, detected, and corrected.

Cover of SCF Overview & Practitioner Guidebook with Secure Controls Framework logo and purpose description for cybersecurity and data privacy practitioners.

Common Controls Framework®

The SCF currently holds the rights to the Common Controls Framework® servicemark. The domains commoncontrolsframework.com and common-controls-framework.com both redirect to the SCF. This distinction is unique among all cybersecurity frameworks and furthers the claim that the it is THE common controls framework.

Common Controls Framework Philosophy

Rosetta Stone Approach To Secure, Compliant & Resilient Capabilities

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Built on the principle that controls are the foundation of any security program, the SCF provides a single, authoritative control catalog that maps to every major cybersecurity and data privacy law, regulation and framework simultaneously. The SCF serves as the “Rosetta Stone” of secure, compliant and resilient capabilities. Organizations can implement SCF controls once and inherit alignment with other frameworks that matter to them.

Secure Controls Framework download
Plan, Do, Check & Act (PDCA) Approach to Cybersecurity governance

Security, Compliance & Resilience Management System (SCRMS)

Our goal is for companies to be secure, compliant and resilient! Those are not just words, since we put a significant amount of time and energy into developing actionable guidance to make that a reality. One major component of that concept is the Security, Compliance & Resilience Management System (SCRMS) - a must-read for any CISO or GRC Director. The SCF can serve as a foundational component for your company to build secure, compliant and resilient capabilities that are able to withstand external scrutiny (e.g., regulators, class action lawsuits, insurers, etc.).

The SCF developed the SCRMS, which is a comprehensive implementation system that treats controls as the central nexus of cybersecurity and data privacy operations. Unlike traditional GRC which is often process-centric, the SCRMS is controls-centric. In the SCRMS, controls are viewed as the nexus , or central pivoting point, for an organization’s cybersecurity program. Not just policies and standards map to controls, but procedures, metrics, threats, and risks as well. This ties everything together into a cohesive, operationalizable framework that any CISO or GRC Director can implement.

The SCF focuses on internal controls. These are the cybersecurity and privacy-related policies, standards, procedures, technologies and associated processes that are designed to provide reasonable assurance that business objectives will be achieved and undesired events will be prevented, detected and corrected.

SCRMS product card showing the Security Compliance and Resilience Management System, a framework-agnostic approach to design, implement, and maintain secure compliant and resilient capabilities

Security, Compliance & Resilience Management System (SCRMS)

The SCRMS is the "how-to" guide for implementing the SCF. It provides a structured, Plan-Do-Check-Act cycle for building and maintaining a cybersecurity and privacy program using the SCF as the foundation.

Cybersecurity & Privacy By Design

The SCF is built on the principle that security and privacy must be "baked in" and not bolted on. Two complementary design philosophies underpin the entire framework.

Security by Design (SbD)

Security by Design means security is addressed at the strategic, operational, and tactical levels. It is built into the design of systems, processes, and products from the start rather than applied as an afterthought. The SCF's 33-domain structure enforces SbD by providing controls at every organizational layer, from governance (GOV) through technical controls (NET, IAC, CRY) and operations (IRO, MON, VPM). Requirements originate from statutory law, regulatory agencies, contractual obligations, and industry best practices. The SCF distills all into a single, consistent security design language usable by teams at any scale.

Privacy by Design (PbD)

Privacy by Design is the principle that privacy must be proactively embedded into the design of IT systems, business practices, and physical infrastructure, not added on but built as a default state. The SCF's Privacy (PRI) domain contains 40+ controls aligned to GDPR, CCPA/CPRA, PIPEDA, and global privacy regulations, covering DSARs, PIAs, DPIAs, consent management, and more. The SCF treats cybersecurity and privacy as inseparable. Both are necessary conditions of a mature, defensible program that can withstand external scrutiny from regulators and auditors.