Secure Controls Framework
Download The SCF

Set Theory Relationship Mapping (STRM)

Starting with release 2024.1, the SCF leverages NIST IR 8477 Set Theory Relationship Mapping for crosswalk mapping. This is the US Government's gold standard for evaluating cybersecurity and data privacy laws, regulations and frameworks.

Need Excel Versions Of STRM?

While the PDF versions of the STRM are free (scroll down the page to see them), the SCF offers editable Excel versions of all STRM mappings. The bundle of Excel versions is $25 (access to redownload is available for 30 days from date of purchase).

Secure Controls Framework - purchase Set Theory Relationship Mapping (STRM)
NIST IR 8477

The Gold Standard for Crosswalk Mapping

NIST IR 8477 provides the definitive practice for crosswalk mapping with no technology needed. It can be performed with a pencil and piece of paper.

Children learn the process of diagramming sentences in grade school (e.g., the Reed–Kellogg model) with pencil and paper. This same process of graphically identifying the relationships between elements forms the basis of STRM. What NIST IR 8477 does is formalize this with Set Theory mathematics to produce rigorous, defensible, and IP-protected crosswalk mappings.

STRM is part of NIST’s broader NIST OLIR Program, an effort to facilitate Subject Matter Experts in defining standardized Online Informative References between elements of their creation and NIST publications. The SCF has been participating in the NIST OLIR program for several years now to help make crosswalk mapping easier and more accessible.

You can click on the image to the side to see a PDF version of how the SCF is utilizing STRM, as well as an example for what that looks like with a few NIST CSF 2.0 controls:

NIST IR 8477 Set Theory Relationship Mapping (STRM) example PDF showing how the SCF maps controls using set theory Venn diagrams with NIST CSF 2.0 crosswalk examples
STRM Methodology

The 5 STRM Relationship Types

Every crosswalk mapping in the SCF uses exactly one of these five mathematically-defined relationship types, ensuring precision and consistency across all 200+ mapped LRF.

STRM Relationship Types
⊂
Subset Of
The LRF requirement is fully contained within the SCF control. The SCF control is broader in scope and coverage.
=
Equal To
The LRF requirement and SCF control are semantically equivalent. They address the same concept at the same scope.
⊃
Superset Of
The SCF control is contained within the LRF requirement. The LRF requirement is broader in scope and coverage.
∩
Intersects With
The LRF requirement and SCF control share partial overlap. Neither is fully contained within the other.
∅
No Relationship
The LRF requirement and SCF control have no meaningful semantic overlap. No mapping is established.

Relationship Strength (1–10)

Relationship Strength (1–10): Each mapping also receives a numeric strength rating. A rating of 1 indicates a nominal relationship, 5 indicates moderately strong, and 10 indicates the strongest relationship, typically reserved for "Equal To" or where the LRF requirement is a "Subset Of" the SCF control.

Methodology Advantage

Expert-Derived Content (EDC) vs. Natural Language Processing (NLP)

The SCF exclusively uses human subject-matter experts to perform STRM crosswalk mapping. This is a deliberate choice with significant IP, legal and quality implications.

SCF: Expert-Derived Content (EDC)

The SCF leverages human SMEs to perform STRM mapping. This produces content that is:

  • Copyright-protected as original work by human creators
  • Patent-eligible under the “mental steps” doctrine
  • Defensible through documented expert judgment
  • Consistent with NIST IR 8477 gold standard practices

Other Vendors: Natural Language Processing (NLP)

AI/NLP-based crosswalk solutions face significant IP limitations:

  • AI-generated content is not copyright-protectable (no human creator)
  • Potentially free to copy under current US copyright rulings
  • Patent claims may be invalid under the 2014 Supreme Court “mental steps” doctrine
  • Quality depends on training data rather than professional expertise

Why it matters

The SCF's EDC approach means its crosswalk mappings are both higher-quality and legally protected intellectual property, which is exactly how NIST IR 8477 itself was designed to work.

SCF Implementation

How the SCF Utilizes STRM

The SCF applies STRM to every one of its 200+ mapped laws, regulations and frameworks. Each mapping documents the precise set-theoretic relationship between every LRF requirement and the corresponding SCF control.

Focal Document Element (FDE)

Each LRF requirement is defined as a Focal Document Element with a unique identifier. Without a unique FDE value, no granular mapping is possible because there is nothing to map to.

SCF Control Mapping

Each FDE is mapped to the most appropriate SCF control with a documented relationship type (Subset Of, Intersects With, Equal To, Superset Of, or No Relationship) and a strength score of 1–10.

Multi-Framework Compliance

Because all LRF are mapped to common SCF controls using STRM, a single SCF control can simultaneously satisfy requirements across dozens of laws, regulations and frameworks. This enables true multi-framework compliance efficiency.

Available STRMs

Published STRM Mappings

Excel versions of the STRM mappings are available for purchase at the SCF Store. The following STRM mappings are currently published:

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
EU
EMEA
✓ STRM
EU - European Union General Data Protection Regulation (2016)
EU
EMEA
✓ STRM
EU - Second Payment Services Directive (PSD2) (2015)
Germany
EMEA
✓ STRM
Germany - Banking Supervisory Requirements for IT (2017)
Germany
EMEA
✓ STRM
Germany - Cloud Computing Compliance Controls Catalogue (C5) (2026)
Germany
EMEA
✓ STRM
Germany - Federal Data Protection Act (2017)
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP)
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - Core Controls
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - High
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - Low
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - Low+
GovRAMP
General
✓ STRM
Government Risk and Authorization Management Program (GovRAMP) - Moderate
Greece
EMEA
✓ STRM
Greece - Protection of Individuals with Regard to the Processing of Personal Data (2472/1997)
Hong Kong
APAC
✓ STRM
Hong Kong - Personal Data Ordinance (2022)
Hungary
EMEA
✓ STRM
Hungary - Act CXII of 2011
India
APAC
✓ STRM
India Digital Personal Data Protection Act (2023)
India
APAC
✓ STRM
India - Information Technology Rules (Privacy Rules) (2011)
India
APAC
✓ STRM
India - SEBI Cybersecurity and Cyber Resilience Framework (2024)
IEC
General
✓ STRM
International Electrotechnical Commission 62443-4-2 Ed. 1.0 b:2019 - Security for industrial automation and control systems - Part 4-2: Technical security requirements for IACS components
IEC
General
✓ STRM
International Electrotechnical Commission (IEC) 62443-2-1:2024 - Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners
IEC
General
✓ STRM
International Electrotechnical Commission (IEC) 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels
IEC
General
✓ STRM
International Electrotechnical Commission (IEC) 62443-4-1:2018 - Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements
IEC
General
✓ STRM
International Electrotechnical Commission (IEC) Technical Report 60601-4-5:2021 - Medical electrical equipment - Part 4-5: Guidance and interpretation - Safety-related technical security specifications
IMO
General
✓ STRM
International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management (2025)
Israel
EMEA
✓ STRM
Ireland - Cybersecurity Methodology for an Organization (CMO) v2.0

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
NIST
General
✓ STRM
NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 1 Baseline
NIST
General
✓ STRM
NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 2 Baseline
NIST
General
✓ STRM
NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 3 Baseline
NIST
General
✓ STRM
NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information
NIST
General
✓ STRM
NIST SP 800-171A R3 - Assessing Security Requirements for Controlled Unclassified Information
NIST
General
✓ STRM
NIST SP 800-171 R2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
NIST
General
✓ STRM
NIST SP 800-171 R3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
NIST
General
✓ STRM
NIST SP 800-172A R3 - Assessing Enhanced Security Requirements for Controlled Unclassified Information
NIST
General
✓ STRM
NIST SP 800-172 R3 - Enhanced Security Requirements for Protecting Controlled Unclassified Information
NIST
General
✓ STRM
NIST SP 800-207 - Zero Trust Architecture
NIST
General
✓ STRM
NIST SP 800-218 - Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities
NIST
General
✓ STRM
NIST SP 800-37 R2 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
NIST
General
✓ STRM
NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View
NIST
General
NIST SP 800-53 R4 - Security and Privacy Controls for Federal Information Systems and Organizations
No STRM available - see NIST SP 800-53 R5
NIST
General
✓ STRM
NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations
NIST
General
✓ STRM
NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - High Baseline
NIST
General
✓ STRM
NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Low Baseline
NIST
General
✓ STRM
NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Moderate Baseline
NIST
General
✓ STRM
NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Privacy Baseline
NIST
General
✓ STRM
NIST SP 800-66 R2 - Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide
NIST
General
✓ STRM
NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - High OT Overlay
NIST
General
✓ STRM
NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay
NIST
General
✓ STRM
NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay
NIST
General
✓ STRM
NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Moderate OT Overlay

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Federal
USA
✓ STRM
USA - 33 CFR Part 101 Subpart F (up to date as of 4-17-2026)
State
USA
✓ STRM
USA - Alaska Personal Information Protection Act (PIPA) (2009)
State
USA
✓ STRM
USA - California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)
State
USA
✓ STRM
USA - California SB1386 (2002)
State
USA
✓ STRM
USA - California SB327 (2018)
Federal
USA
✓ STRM
USA - Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0
Federal
USA
✓ STRM
USA - Children's Online Privacy Protection Act (COPPA) (2024)
State
USA
✓ STRM
USA - Colorado Privacy Act (2021)
Federal
USA
✓ STRM
USA - Cybersecurity & Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals 2.0
Federal
USA
✓ STRM
USA - Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)
Federal
USA
✓ STRM
USA - Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog
Federal
USA
✓ STRM
USA - Data Privacy Framework (2023)
Federal
USA
✓ STRM
USA - Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012
Federal
USA
✓ STRM
USA - Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1
Federal
USA
✓ STRM
USA - Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0
Federal
USA
✓ STRM
USA - Department of War (DoW) - Computer Emergency Response Team (CERT) Resilience Management Model (RMM) Version 1.2
Federal
USA
✓ STRM
USA - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1
Federal
USA
✓ STRM
USA - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1 Assessment Objectives
Federal
USA
✓ STRM
USA - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 2
Federal
USA
✓ STRM
USA - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 3
Federal
USA
✓ STRM
USA - Department of War (DoW) - Zero Trust Execution Roadmap v1.1
Federal
USA
✓ STRM
USA - Department of War (DoW) - Zero Trust Reference Architecture v2
USA - Federal
USA
✓ STRM
USA - DoW Brilliant at the Basics: Top 10 IT Cybersecurity Best Practices for DIB Partners
USA - Federal
USA
✓ STRM
USA - DoW Brilliant at the Basics: Top 10 OT Cybersecurity Best Practices for DIB Partners

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Austria
EMEA
✓ STRM
Austria - Data Protection Act (2018)
Belgium
EMEA
✓ STRM
Belgium - Act of 30 July 2018
Switzerland
EMEA
✓ STRM
CHE - FINMA Circular 2023/1 - Operational Risks and Resilience - Banks
Luxembourg
EMEA
✓ STRM
Commission de Surveillance du Secteur Financier (CSSF) Circular 20/750 - ICT Risk Management (2020)
Luxembourg
EMEA
✓ STRM
Commission de Surveillance du Secteur Financier (CSSF) Circular 22/806 (as amended by Circulars CSSF 25/883 and 26/915) - Outsourcing Arrangements (2022)
EU
EMEA
✓ STRM
EU - Digital Operational Resilience Act (2023)
EU
EMEA
✓ STRM
EU - DORA Draft RTS on ICT Risk Management Framework and on Simplified ICT Risk Management Framework (JC 2023 86)
EU
EMEA
✓ STRM
EU - European Banking Authority Guidelines on ICT and Security Risk Management (2025)
EU
EMEA
✓ STRM
EU - European Union Agency for Cybersecurity NIS2 Annex (2024)
EU
EMEA
✓ STRM
EU - European Union Agency for Cybersecurity NIS2 Directive (EU) 2022/2555)
EU
EMEA
✓ STRM
EU - European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)
EU
EMEA
✓ STRM
EU - European Union Cyber Resilience Act (2024)
EU
EMEA
✓ STRM
EU - European Union Cyber Resilience Act - Annex I (2024)
EU
EMEA
✓ STRM
EU - European Union General Data Protection Regulation (2016)
EU
EMEA
✓ STRM
EU - Second Payment Services Directive (PSD2) (2015)
Germany
EMEA
✓ STRM
Germany - Banking Supervisory Requirements for IT (2017)
Germany
EMEA
✓ STRM
Germany - Cloud Computing Compliance Controls Catalogue (C5) (2026)
Germany
EMEA
✓ STRM
Germany - Federal Data Protection Act (2017)
Greece
EMEA
✓ STRM
Greece - Protection of Individuals with Regard to the Processing of Personal Data (2472/1997)
Hungary
EMEA
✓ STRM
Hungary - Act CXII of 2011
Israel
EMEA
✓ STRM
Ireland - Cybersecurity Methodology for an Organization (CMO) v2.0
Ireland
EMEA
✓ STRM
Ireland - Data Protection Act (DPA) (2018)
Israel
EMEA
✓ STRM
Israel - Protection of Privacy Law, 5741 (2025)
Italy
EMEA
✓ STRM
Italy - Personal Data Protection Code (2018)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Australia
APAC
✓ STRM
Australia - Cloud Controls Matrix (June 2026)
Australia
APAC
✓ STRM
Australia - Code of Practice - Securing the Internet of Things for Consumers (2020)
Australia
APAC
✓ STRM
Australia - Essential Eight maturity model and ISM mapping (2024)
Australia
APAC
✓ STRM
Australia - Information Security Manual (ISM) (June 2026)
Australia
APAC
✓ STRM
Australia - Privacy Principles (2026)
Australia
APAC
✓ STRM
Australia - Prudential Standard CPS 230 - Operational Risk Management (2023)
Australia
APAC
✓ STRM
Australia - Prudential Standard CPS 234 Information Security (2019)
Australia
APAC
✓ STRM
Australia - Security of Critical Infrastructure Act 2018 (Compilation No. 9, 4 June 2026)
China
APAC
✓ STRM
China - Cybersecurity Law of the People's Republic of China (2017)
China
APAC
✓ STRM
China - Data Security Law of the People's Republic of China (2021)
China
APAC
✓ STRM
China - Decision on Strengthening Network Information Protection (2012)
China
APAC
✓ STRM
China - Personal Information Protection Law of the People's Republic of China (2021)
Hong Kong
APAC
✓ STRM
Hong Kong - Personal Data Ordinance (2022)
India
APAC
✓ STRM
India Digital Personal Data Protection Act (2023)
India
APAC
✓ STRM
India - Information Technology Rules (Privacy Rules) (2011)
India
APAC
✓ STRM
India - SEBI Cybersecurity and Cyber Resilience Framework (2024)
Japan
APAC
✓ STRM
Japan - Act on the Protection of Personal Information (2020)
Japan
APAC
✓ STRM
Japan - Information System Security Management and Assessment Program (ISMAP)
Malaysia
APAC
✓ STRM
Malaysia - Personal Data Protection Act (PDPA) (2010)
Malaysia
APAC
✓ STRM
Malaysia - Risk Management in Technology (RMiT) (2025)
New Zealand
APAC
✓ STRM
New Zealand - HISF MicroSmall (2023)
New Zealand
APAC
✓ STRM
New Zealand - HISF MLHSP (2023)
New Zealand
APAC
✓ STRM
New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers
New Zealand
APAC
✓ STRM
New Zealand - Information Security Manual (ISM) v3.9

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Argentina
Americas
✓ STRM
Argentina - Protection of Personal Data (2018)
Bahamas
Americas
✓ STRM
Bahamas - Data Protection Act (DPA) (2003)
Bermuda
Americas
✓ STRM
Bermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)
Brazil
Americas
✓ STRM
Brazil - General Data Protection Law (LGPD) (2018)
Canada
Americas
✓ STRM
Canada - OSFI B-13 (2022)
Canada
Americas
✓ STRM
Canada - OSFI Cyber Security Self-Assessment Guidance
Canada
Americas
✓ STRM
Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)
Canada
Americas
✓ STRM
Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171) (2025)
Chile
Americas
✓ STRM
Chile - Act 19628 - Protection of Personal Data (1999)
Colombia
Americas
✓ STRM
Colombia - Law 1581 (2012)
Mexico
Americas
✓ STRM
Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010)

No matching frameworks found. Try a different search term or filter.

Community Involvement

How To Submit a Community STRM Mapping

The SCF welcomes community involvement. The SCF Council provides a downloadable Community STRM Template that practitioners can use to perform their own crosswalk mapping and submit for possible inclusion in a future SCF release.

01

Define the Focal Document

Open the STRM template’s “STRM Overview” tab and complete the two highlighted cells identifying:

  • The Focal Document (FD), which is the law, regulation or framework you are mapping
  • The Reference Document (RD), which is the SCF (the document being mapped to)

Prerequisites: familiarity with NIST IR 8477 and professional competence to conduct crosswalk mapping.

02

Perform the STRM Mapping

Complete the “Community STRM submission” tab using these columns:

  • FDE number (mandatory unique identifier)
  • FDE name (if available)
  • FDE description (exact text of the requirement)
  • Proposed SCF control name
  • SCF control number
  • SCF control description
  • STRM relationship type (1 of 5 options)
  • Relationship strength (1–10 rating)
  • Optional notes / justification
03

Submit to the SCF Council

Once your STRM exercise is complete, email the completed Excel spreadsheet to the SCF Council for review:

support@securecontrolsframework.com

Submissions are evaluated by the SCF Council and may be included in a future SCF release. The SCF Council will contact you if there are questions about your submission.