SCR-RMM: Risk Management Model
The Secure, Compliant & Resilient Risk Management Model (SCR-RMM) is a free, structured methodology to identify, assess, report and mitigate risk. Jointly developed by ComplianceForge and the SCF Council, the SCR-RMM breaks risk management down into seventeen (17) distinctive steps, from establishing risk management principles through implementing and documenting risk treatment.
17 Risk Steps
27 Threats Cataloged
4 Risk Determinations
FREE Creative Commons
Download the SCR-RMM
An Efficient Methodology to Identify, Assess, Report & Mitigate Risk
The concept of creating the SCR-RMM was to establish an efficient methodology to identify, assess, report and mitigate risk across the entire organization. The project was a collaboration between ComplianceForge and the SCF, approached from the perspective of asking: "How should I manage risk?"
The SCR-RMM is designed to be an integral tool of an organization's ability to demonstrate evidence of due diligence and due care. This not only benefits your organization by having solid risk management practices, but it can also serve as a way to reduce risk for those who have to initiate the hard discussions on risk management topics.
Strategic, Operational & Tactical Risk Considerations
The SCR-RMM integrates risk management with business planning at three levels: strategic, operational, and tactical. Each level has distinct risk management considerations and decision-making authority.
Strategic (Risk Appetite)
Risk appetite is defined at the corporate level. It affects strategic actions and decisions that define the types and amount of risk an organization is willing to accept.
- Mission & Vision
- Strategy
- Compliance Obligations
- Risk Appetite
Operational (Risk Tolerance)
Risk tolerance is put into practice at the Line of Business (LOB) level. It affects operational actions, decisions and resource allocation.
- LOB Objectives
- Capability Maturity Targets
- Resource Prioritization
- Risk Tolerance
Tactical (Risk Thresholds)
Risk thresholds affect actions and decisions at the department and team levels.
- Processes & Technologies
- Staffing & Supply Chain
- Compliance Obligations
- Risk Appetite
Seventeen Steps, Start to Finish
The SCR-RMM breaks risk management down into 17 distinctive steps, providing coverage from start to finish, establishing risk management principles through implementing and documenting risk treatment.
| Step | Name | Activity |
|---|---|---|
| 1 | Identify Risk Management Principles | Establish the foundational risk management principles that will govern the organization's approach. |
| 2 | Identify, Implement & Document Critical Dependencies | Identify risk management dependencies, technology dependencies, and business dependencies. |
| 3 | Formalize Risk Management Practices | Establish formal, documented risk management practices integrated into business-as-usual activities. |
| 4 | Establish a Risk Catalog | Define applicable risks based on control deficiencies. |
| 5 | Establish a Threat Catalog | Identify natural and man-made threats. |
| 6 | Establish a Controls Catalog | Define applicable cybersecurity and data privacy controls based on statutory, regulatory, and contractual obligations. |
| 7 | Define CMM Targets | Set Capability Maturity Model targets for the organization's controls using the SCR-CMM. |
| 8 | Define Assessment Rigor | Select the appropriate rigor level: Standard, Enhanced, or Comprehensive. |
| 9 | Establish Context for Assessing Risks | Establish the organizational and environmental context for the risk assessment. |
| 10 | Conformity Assessment (Controls Gap Assessment) | Conduct the gap assessment against the controls catalog to identify deficiencies. |
| 11 | Control Assessment Methods & Findings | Apply assessment methods, methodologies, and document assessment findings. |
| 12 | Determine Risk Exposure | Calculate Impact Effect, Occurrence Likelihood, Inherent Risk, and Residual Risk. |
| 13 | Prioritize & Document Identified Deficiencies | Prioritize findings based on risk exposure and document all identified deficiencies. |
| 14 | Risk Determination: Report on Conformity (ROC) | Categorize results as: Strictly Conforms, Conforms, Significant Deficiency, or Material Weakness. |
| 15 | Identify the Appropriate Management Audience | Determine which level of management has legitimate authority for risk decisions. |
| 16 | Management Determines Risk Treatment | LOB management decides: reduce, avoid, transfer, or accept the risk. |
| 17 | Implement & Document Risk Treatment | Cybersecurity and data protection practitioners implement and document the selected treatment. |
SCF Threat Catalog
Natural & Man-Made Threats
The SCF Threat Catalog answers the question: "What natural and man-made threats affect control execution?" If the threat materializes, will the control function as expected?
| Threat | # | Threat Name | Threat Description |
|---|---|---|---|
| NT-1 | Drought & Water Shortage | Periods of reduced rainfall expected. | |
| NT-2 | Earthquakes | Sudden rolling or shaking events caused by movement under the earth’s surface. | |
| NT-3 | Fire & Wildfires | Concern for every business. | |
| NT-4 | Floods | The most common of natural hazards. | |
| NT-5 | Hurricanes & Tropical Storms | Powerful natural disasters due to size and destructive potential. | |
| NT-6 | Landslides & Debris Flow | Can be caused by various factors including human modification of land. | |
| NT-7 | Pandemic (Disease) Outbreaks | Consideration should be given to possible scenarios during a pandemic. | |
| ... | ... | ... | ... |
| MT-1 | Civil or Political Unrest | Unexpected and unpredictable events. | |
| MT-2 | Hacking & Cybersecurity Crimes | Difficult to identify during occurrence. | |
| MT-3 | Hazardous Materials Emergencies | Accidental disasters in industrialized nations. | |
| ... | ... | ... | ... |
Risk Categories: What Happens When Controls Fail
Risks are organized into eight groupings, answering: "What are the risks associated with a control deficiency?"
| Risk # | Risk Name | Risk Description |
|---|---|---|
| R-AC-1 | Inability to maintain individual accountability | The inability to maintain accountability. |
| R-AC-2 | Improper assignment of privileged functions | Inability to implement least privileges. |
| R-BC-1 | Business interruption | Increased latency or service outage. |
| ... | ... | ... |
Risk Determinations
Four Risk Conformity Designations
- Strictly Conforms: Full conformity to all applicable controls.
- Conforms: Minor deficiencies that do not materially impact the overall risk posture.
- Significant Deficiency: Control deficiencies warranting attention.
- Material Weakness: Deficiencies affecting assurance of the organization's risk tolerance.
SCR-RMM Works With the SCF Ecosystem
The SCR-RMM integrates with the full SCF assessment ecosystem, utilizing various tools for risk management.
SCR-CMM Maturity Model
SCF Control Catalog
CDPAS Assessment Standards
Evidence Request List (ERL)
Unified Scoping Guide (USG)
SCF-CAP Conformity Assessment
Continuous Improvement
The SCR-RMM operates within a continuous improvement cycle, treating risk management as an ongoing capability integrated into business-as-usual activities.