SCR-CMM: Capability Maturity Model. Measure & Advance Your Cybersecurity Program

The Secure, Compliant & Resilient Capability Maturity Model (SCR-CMM) provides a six-level (L0–L5) maturity scoring system for every control in the Secure Controls Framework (SCF), enabling organizations to objectively assess where they are today, define where they need to be, and measure progress over time. Built on the SSE-CMM v2.0 structure.

6

Maturity Levels (L0–L5)

1,400+

Controls with CMM Criteria

33

Domains Assessed

FREE

Creative Commons

About SCR-CMM

Beyond Compliance: Measure Cybersecurity Capability Maturity

The SCR-CMM is meant to solve the problem of objectivity in both establishing and evaluating cybersecurity and data privacy controls. It draws upon the high-level structure of the Systems Security Engineering Capability Maturity Model v2.0 (SSE-CMM).

A binary pass/fail assessment answers the question “Are we compliant?” The SCR-CMM answers a far more useful question: “How well are we actually doing this?” Compliance frameworks tell organizations what controls to implement, but they do not provide a meaningful way to measure whether those controls are implemented effectively, consistently, or sustainably.

Four Core Objectives of the SCR-CMM

  • Provide CISO/CPOs/CIOs with objective criteria to establish expectations for a cybersecurity & privacy program.
  • Provide objective criteria for project teams to appropriately plan and budget.
  • Provide minimum criteria to evaluate third-party service provider controls.
  • Provide a means to perform due diligence of cybersecurity and privacy practices as part of Mergers & Acquisitions (M&A).

Methodology

Nested Approach to Maturity

By using the term “nested,” we refer to how the SCR-CMM’s control criteria were written to acknowledge that each succeeding level of maturity is built upon its predecessor. Essentially, you cannot run without first learning how to walk.

This approach to defining cybersecurity & privacy control maturity is how the SCR-CMM is structured. The following two questions should be kept in mind when evaluating the maturity of a control (or Assessment Objective):

  • **_