Secure Controls Framework
Download The SCF

Set Theory Relationship Mapping (STRM)

Starting with release 2024.1, the SCF leverages NIST IR 8477 Set Theory Relationship Mapping for crosswalk mapping. This is the US Government's gold standard for evaluating cybersecurity and data privacy laws, regulations and frameworks.

Need Excel Versions Of STRM?

While the PDF versions of the STRM are free (scroll down the page to see them), the SCF offers editable Excel versions of all STRM mappings. The bundle of Excel versions is $25 (access to redownload is available for 30 days from date of purchase).

Secure Controls Framework - purchase Set Theory Relationship Mapping (STRM)
5
Relationship Types
200+
LRF Mapped
NIST IR 8477
Gold Standard
EDC
Expert-Derived Content
NIST IR 8477

The Gold Standard for Crosswalk Mapping

NIST IR 8477 provides the definitive practice for crosswalk mapping with no technology needed. It can be performed with a pencil and piece of paper.

Children learn the process of diagramming sentences in grade school (e.g., the Reed–Kellogg model) with pencil and paper. This same process of graphically identifying the relationships between elements forms the basis of STRM. What NIST IR 8477 does is formalize this with Set Theory mathematics to produce rigorous, defensible, and IP-protected crosswalk mappings.

STRM is part of NIST’s broader NIST OLIR Program, an effort to facilitate Subject Matter Experts in defining standardized Online Informative References between elements of their creation and NIST publications. The SCF has been participating in the NIST OLIR program for several years now to help make crosswalk mapping easier and more accessible.

You can click on the image to the side to see a PDF version of how the SCF is utilizing STRM, as well as an example for what that looks like with a few NIST CSF 2.0 controls:

NIST IR 8477 Set Theory Relationship Mapping (STRM) example PDF showing how the SCF maps controls using set theory Venn diagrams with NIST CSF 2.0 crosswalk examples
STRM Methodology

The 5 STRM Relationship Types

Every crosswalk mapping in the SCF uses exactly one of these five mathematically-defined relationship types, ensuring precision and consistency across all 200+ mapped LRF.

Subset Of

The LRF requirement is fully contained within the SCF control. The SCF control is broader in scope and coverage.

Intersects With

The LRF requirement and SCF control share partial overlap. Neither is fully contained within the other.

=

Equal To

The LRF requirement and SCF control are semantically equivalent. They address the same concept at the same scope.

Superset Of

The SCF control is contained within the LRF requirement. The LRF requirement is broader in scope and coverage.

Ø

No Relationship

The LRF requirement and SCF control have no meaningful semantic overlap. No mapping is established.

Relationship Strength (1–10)

Relationship Strength (1–10): Each mapping also receives a numeric strength rating. A rating of 1 indicates a nominal relationship, 5 indicates moderately strong, and 10 indicates the strongest relationship, typically reserved for "Equal To" or where the LRF requirement is a "Subset Of" the SCF control.

Methodology Advantage

Expert-Derived Content (EDC) vs. Natural Language Processing (NLP)

The SCF exclusively uses human subject-matter experts to perform STRM crosswalk mapping. This is a deliberate choice with significant IP, legal and quality implications.

SCF: Expert-Derived Content (EDC)

The SCF leverages human SMEs to perform STRM mapping. This produces content that is:

  • Copyright-protected as original work by human creators
  • Patent-eligible under the “mental steps” doctrine
  • Defensible through documented expert judgment
  • Consistent with NIST IR 8477 gold standard practices

Other Vendors: Natural Language Processing (NLP)

AI/NLP-based crosswalk solutions face significant IP limitations:

  • AI-generated content is not copyright-protectable (no human creator)
  • Potentially free to copy under current US copyright rulings
  • Patent claims may be invalid under the 2014 Supreme Court “mental steps” doctrine
  • Quality depends on training data rather than professional expertise

Why it matters

The SCF's EDC approach means its crosswalk mappings are both higher-quality and legally protected intellectual property, which is exactly how NIST IR 8477 itself was designed to work.

SCF Implementation

How the SCF Utilizes STRM

The SCF applies STRM to every one of its 200+ mapped laws, regulations and frameworks. Each mapping documents the precise set-theoretic relationship between every LRF requirement and the corresponding SCF control.

Focal Document Element (FDE)

Each LRF requirement is defined as a Focal Document Element with a unique identifier. Without a unique FDE value, no granular mapping is possible because there is nothing to map to.

SCF Control Mapping

Each FDE is mapped to the most appropriate SCF control with a documented relationship type (Subset Of, Intersects With, Equal To, Superset Of, or No Relationship) and a strength score of 1–10.

Multi-Framework Compliance

Because all LRF are mapped to common SCF controls using STRM, a single SCF control can simultaneously satisfy requirements across dozens of laws, regulations and frameworks. This enables true multi-framework compliance efficiency.

Available STRMs

Published STRM Mappings

Excel versions of the STRM mappings are available for purchase at the SCF Store. The following STRM mappings are currently published:

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
EMEA
✓ STRM
Qatar
Qatar - Personal Data Privacy Protection Law (PDPPL) (2020)
EMEA
✓ STRM
Russia
Russia - Federal Law No. 152-FZ (2025)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Critical Systems Cybersecurity Controls (CSCC – 1: 2019)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Cybersecurity Guidelines for Internet of Things (CGIoT - 1:2024)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Essential Cybersecurity Controls (ECC – 1 : 2018)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Operational Technology Cybersecurity Controls (OTCC-1: 2022)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Personal Data Protection Law (PDPL) (2023)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - SACS-002 Third Party Cybersecurity Standard (2022)
EMEA
✓ STRM
Saudi Arabia
Saudi Arabia - Saudi Arabian Monetary Authority (SAMA) Cyber Security Framework Version 1.0 (2017)
General
✓ STRM
SCF
Secure Controls Framework (SCF) Data Privacy Management Principles (2025)
EMEA
✓ STRM
Serbia
Serbia - Act of 9 November 2018 on Personal Data Protection (Official Gazette No. 87/18)
General
Shared Assessments
Shared Assessments Standard Information Gathering (SIG) Questionnaire 2025
No STRM available - mapping provided by Shared Assessments
APAC
✓ STRM
Singapore
Singapore - Cyber Hygiene Practice (2019)
APAC
✓ STRM
Singapore
Singapore - Monitory Authority of Singapore (MAS) Technology Risk Management (TRM) Guidelines (2021)
APAC
✓ STRM
Singapore
Singapore - Personal Data Protection Ac (PDPA) (2012)
General
✓ STRM
SWIFT
Society for Worldwide Interbank Financial Telecommunication Customer Security Controls Framework 2025
EMEA
✓ STRM
South Africa
South Africa - Protection of Personal Information Act (POPIA) (2013)
APAC
✓ STRM
South Korea
South Korea - Personal Information Protection Act (PIPA) (2011)
General
✓ STRM
SPARTA
Space Attack Research & Tactic Analysis (SPARTA) Countermeasures
EMEA
✓ STRM
Spain
Spain - ICT Security Guide CCN-STIC 825 (2026)
EMEA
✓ STRM
Spain
Spain - Royal Decree 311/2022
EMEA
✓ STRM
Switzerland
Switzerland - Federal Act on Data Protection (FADP) (2025)
APAC
✓ STRM
Taiwan
Taiwan - Personal Data Protection Act (PDPA) (2025)
General
✓ STRM
TISAX
Trusted Information Security Assessment Exchange (TISAX) 6.0.3

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
General
✓ STRM
IMO
International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management (2025)
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 22301:2019 - Security and resilience - Business continuity management systems - Requirements
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 27017:2015 - Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 27018:2025 - Information security, cybersecurity and privacy protection - Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 29100:2024 - Information technology - Security techniques - Privacy framework
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 31000:2018 - Risk management - Guidelines
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 31010:2019 - Risk management - Risk assessment techniques
Download STRM (PDF)
General
✓ STRM
ISO
ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system
Download STRM (PDF)
General
✓ STRM
IEC
ISO/SAE 21434:2021 - Road vehicles — Cybersecurity engineering
Download STRM (PDF)
General
✓ STRM
MITRE
MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) - NIST 800-53 mappings
Download STRM (PDF)
General
✓ STRM
MPA
Motion Picture Association (MPA) Content Security Best Practices Common Guidelines v5.3.1
Download STRM (PDF)
General
✓ STRM
NAIC
National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law (MDL-668) (2017)
Download STRM (PDF)
General
✓ STRM
NIST
NIST AI 100-1 - Artificial Intelligence Risk Management Framework (AI RMF 1.0)
Download STRM (PDF)
General
✓ STRM
NIST
NIST AI 600-1 - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
Download STRM (PDF)
General
✓ STRM
NIST
NIST CSWP 39 - Considerations for Achieving Crypto Agility
Download STRM (PDF)
General
✓ STRM
NIST
NIST Cybersecurity Framework v2.0
Download STRM (PDF)
General
✓ STRM
NIST
NIST Privacy Framework v1.0
Download STRM (PDF)
General
✓ STRM
NIST
NIST SP 800-160 Volume 2, Revision 1 - Developing Cyber-Resilient Systems: A Systems Security Engineering Approach
Download STRM (PDF)
General
✓ STRM
NIST
NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
Download STRM (PDF)
General
✓ STRM
NIST
NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - C-SCRM Baseline
Download STRM (PDF)
General
✓ STRM
NIST
NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Flow Down Baseline
Download STRM (PDF)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
USA
✓ STRM
Federal
US - 33 CFR Part 101 Subpart F (up to date as of 4-17-2026)
Download STRM (PDF)
USA
✓ STRM
State
US - Alaska Personal Information Protection Act (PIPA) (2009)
Download STRM (PDF)
USA
✓ STRM
State
US - California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)
Download STRM (PDF)
USA
✓ STRM
State
US - California SB1386 (2002)
Download STRM (PDF)
USA
✓ STRM
State
US - California SB327 (2018)
Download STRM (PDF)
USA
✓ STRM
Federal
US - Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0
Download STRM (PDF)
USA
✓ STRM
Federal
US - Children's Online Privacy Protection Act (COPPA) (2024)
Download STRM (PDF)
USA
✓ STRM
State
US - Colorado Privacy Act (2021)
Download STRM (PDF)
USA
✓ STRM
Federal
US - Cybersecurity & Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals 2.0
Download STRM (PDF)
USA
✓ STRM
Federal
US - Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)
Download STRM (PDF)
USA
✓ STRM
Federal
US - Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog
Download STRM (PDF)
USA
✓ STRM
Federal
US - Data Privacy Framework (2023)
Download STRM (PDF)
USA
✓ STRM
Federal
US - Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012
Download STRM (PDF)
USA
✓ STRM
Federal
US - Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1
Download STRM (PDF)
USA
✓ STRM
Federal
US - Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0
Download STRM (PDF)
USA
✓ STRM
Federal
US - Department of War (DoW) - Computer Emergency Response Team (CERT) Resilience Management Model (RMM) Version 1.2
Download STRM (PDF)
USA
✓ STRM
Federal
US - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1
Download STRM (PDF)
USA
✓ STRM
Federal
US - Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 1 Assessment Objectives
Download STRM (PDF)
USA
✓ STRM
Federal
US Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 2
Download STRM (PDF)
USA
✓ STRM
Federal
US Department of War (DoW) - Cybersecurity Maturity Model Certification (CMMC) v2.0 - Level 3
Download STRM (PDF)
USA
✓ STRM
Federal
US - Department of War (DoW) - Zero Trust Execution Roadmap v1.1
Download STRM (PDF)
USA
✓ STRM
Federal
US - Department of War (DoW) - Zero Trust Reference Architecture v2
Download STRM (PDF)
USA
✓ STRM
Federal
US - Executive Order (EO) 14028 - Improving the Nation's Cybersecurity
Download STRM (PDF)
USA
✓ STRM
Federal
US - Fair & Accurate Credit Transactions Act (FACTA) & Fair Credit Reporting Act (FCRA) (2023)
Download STRM (PDF)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
EMEA
✓ STRM
Austria
Austria - Data Protection Act (2018)
Download STRM (PDF)
EMEA
✓ STRM
Belgium
Belgium - Act of 30 July 2018
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - Digital Operational Resilience Act (2023)
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - European Banking Authority Guidelines on ICT and Security Risk Management (2025)
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - European Union Agency for Cybersecurity NIS2 Annex (2024)
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - European Union Agency for Cybersecurity NIS2 Directive (EU) 2022/2555)
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - European Union Cyber Resilience Act (2024)
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - European Union Cyber Resilience Act - Annex I (2024)
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - European Union General Data Protection Regulation (2016)
Download STRM (PDF)
EMEA
✓ STRM
EU
EU - Second Payment Services Directive (PSD2) (2015)
Download STRM (PDF)
EMEA
✓ STRM
Germany
Germany - Banking Supervisory Requirements for IT (2017)
Download STRM (PDF)
EMEA
✓ STRM
Germany
Germany - Cloud Computing Compliance Controls Catalogue (C5) (2020)
Download STRM (PDF)
EMEA
✓ STRM
Germany
Germany - Federal Data Protection Act (2017)
Download STRM (PDF)
EMEA
✓ STRM
Greece
Greece - Protection of Individuals with Regard to the Processing of Personal Data (2472/1997)
Download STRM (PDF)
EMEA
✓ STRM
Hungary
Hungary - Act CXII of 2011
Download STRM (PDF)
EMEA
✓ STRM
Israel
Ireland - Cybersecurity Methodology for an Organization (CMO) v2.0
Download STRM (PDF)
EMEA
✓ STRM
Ireland
Ireland - Data Protection Act (DPA) (2018)
Download STRM (PDF)
EMEA
✓ STRM
Israel
Israel - Protection of Privacy Law, 5741 (2025)
Download STRM (PDF)
EMEA
✓ STRM
Italy
Italy - Personal Data Protection Code (2018)
Download STRM (PDF)
EMEA
✓ STRM
Kenya
Kenya - Data Protection Act (DPA) (2019)
Download STRM (PDF)
EMEA
✓ STRM
Nigeria
Nigeria - Data Protection Regulation (DPR) (2019)
Download STRM (PDF)
EMEA
✓ STRM
Norway
Norway - Personal Data Act (PDA) (2018)
Download STRM (PDF)
EMEA
✓ STRM
Poland
Poland - Act of 10 May 2018 on the Protection of Personal Data
Download STRM (PDF)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
APAC
✓ STRM
Australia
Australia - Code of Practice - Securing the Internet of Things for Consumers (2020)
Download STRM (PDF)
APAC
✓ STRM
Australia
Australia - Essential Eight maturity model and ISM mapping (2024)
Download STRM (PDF)
APAC
✓ STRM
Australia
Australia - Information Security Manual (ISM) (March 2026)
Download STRM (PDF)
APAC
✓ STRM
Australia
Australia - Privacy Principles (2026)
Download STRM (PDF)
APAC
✓ STRM
Australia
Australia - Prudential Standard CPS 230 - Operational Risk Management (2023)
Download STRM (PDF)
APAC
✓ STRM
Australia
Australia - Prudential Standard CPS 234 Information Security (2019)
Download STRM (PDF)
APAC
✓ STRM
China
China - Cybersecurity Law of the People's Republic of China (2017)
Download STRM (PDF)
APAC
✓ STRM
China
China - Data Security Law of the People's Republic of China (2021)
Download STRM (PDF)
APAC
✓ STRM
China
China - Decision on Strengthening Network Information Protection (2012)
Download STRM (PDF)
APAC
✓ STRM
China
China - Personal Information Protection Law of the People's Republic of China (2021)
Download STRM (PDF)
APAC
✓ STRM
Hong Kong
Hong Kong - Personal Data Ordinance (2022)
Download STRM (PDF)
APAC
✓ STRM
India
India Digital Personal Data Protection Act (2023)
Download STRM (PDF)
APAC
✓ STRM
India
India - Information Technology Rules (Privacy Rules) (2011)
Download STRM (PDF)
APAC
✓ STRM
India
India - SEBI Cybersecurity and Cyber Resilience Framework (2024)
Download STRM (PDF)
APAC
✓ STRM
Japan
Japan - Act on the Protection of Personal Information (2020)
Download STRM (PDF)
APAC
✓ STRM
Japan
Japan - Information System Security Management and Assessment Program (ISMAP)
Download STRM (PDF)
APAC
✓ STRM
Malaysia
Malaysia - Personal Data Protection Act (PDPA) (2010)
Download STRM (PDF)
APAC
✓ STRM
Malaysia
Malaysia - Risk Management in Technology (RMiT) (2025)
Download STRM (PDF)
APAC
✓ STRM
New Zealand
New Zealand - HISF MicroSmall (2023)
Download STRM (PDF)
APAC
✓ STRM
New Zealand
New Zealand - HISF MLHSP (2023)
Download STRM (PDF)
APAC
✓ STRM
New Zealand
New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers
Download STRM (PDF)
APAC
✓ STRM
New Zealand
New Zealand - Information Security Manual (ISM) v3.9
Download STRM (PDF)
APAC
✓ STRM
New Zealand
New Zealand - Privacy Act (2020)
Download STRM (PDF)
APAC
✓ STRM
Philippines
Philippines - Data Privacy Act (DPA) (2012)
Download STRM (PDF)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Americas
✓ STRM
Argentina
Argentina - Protection of Personal Data (2018)
Download STRM (PDF)
Americas
✓ STRM
Bahamas
Bahamas - Data Protection Act (DPA) (2003)
Download STRM (PDF)
Americas
✓ STRM
Bermuda
Bermuda - Bermuda Monetary Authority (BMA) Insurance Sector Operational Cyber Risk Management Code of Conduct (2020)
Download STRM (PDF)
Americas
✓ STRM
Brazil
Brazil - General Data Protection Law (LGPD) (2018)
Download STRM (PDF)
Americas
✓ STRM
Canada
Canada - Office of the Superintendent of Financial Institutions Canada (OSFI) - Cyber Security Self-Assessment Guidance
Download STRM (PDF)
Americas
✓ STRM
Canada
Canada - OSFI B-13 (2022)
Download STRM (PDF)
Americas
✓ STRM
Canada
Canada - OSFI Cyber Security Self-Assessment Guidance
Download STRM (PDF)
Americas
✓ STRM
Canada
Canada - Personal Information Protection and Electronic Documents Act (PIPEDA) (2000)
Download STRM (PDF)
Americas
✓ STRM
Canada
Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171) (2025)
Download STRM (PDF)
Americas
✓ STRM
Chile
Chile - Act 19628 - Protection of Personal Data (1999)
Download STRM (PDF)
Americas
✓ STRM
Colombia
Colombia - Law 1581 (2012)
Download STRM (PDF)
Americas
✓ STRM
Mexico
Mexico - Federal Law on Protection of Personal Data held by Private Parties (2010)
Download STRM (PDF)

No matching frameworks found. Try a different search term or filter.

Community Involvement

How To Submit a Community STRM Mapping

The SCF welcomes community involvement. The SCF Council provides a downloadable Community STRM Template that practitioners can use to perform their own crosswalk mapping and submit for possible inclusion in a future SCF release.

01

Define the Focal Document

Open the STRM template’s “STRM Overview” tab and complete the two highlighted cells identifying:

  • The Focal Document (FD), which is the law, regulation or framework you are mapping
  • The Reference Document (RD), which is the SCF (the document being mapped to)

Prerequisites: familiarity with NIST IR 8477 and professional competence to conduct crosswalk mapping.

02

Perform the STRM Mapping

Complete the “Community STRM submission” tab using these columns:

  • FDE number (mandatory unique identifier)
  • FDE name (if available)
  • FDE description (exact text of the requirement)
  • Proposed SCF control name
  • SCF control number
  • SCF control description
  • STRM relationship type (1 of 5 options)
  • Relationship strength (1–10 rating)
  • Optional notes / justification
03

Submit to the SCF Council

Once your STRM exercise is complete, email the completed Excel spreadsheet to the SCF Council for review:

support@securecontrolsframework.com

Submissions are evaluated by the SCF Council and may be included in a future SCF release. The SCF Council will contact you if there are questions about your submission.