Common Cybersecurity Frameworks

Cybersecurity frameworks are voluntary best-practice guidance, not laws. But they define the industry standard for "reasonable" security and are increasingly required by contract, regulation, or as a condition of doing business. Here is what the major frameworks actually are, what they require, and how the SCF CCF™ supersedes them all.

Major Cybersecurity Frameworks

The Most Widely Used Cybersecurity Frameworks

These are the frameworks most commonly required by contracts, mentioned in regulatory guidance, and used by security teams as program baselines. All are mapped in the SCF CCF™.

NIST CSF 2.0

  • Description: NIST Cybersecurity Framework, Version 2.0 (2024)
  • Cost: Free
  • Voluntary: Yes
  • Applicable Sectors: All Sectors
  • Created by: NIST (National Institute of Standards and Technology)
  • Structure: 6 Functions (Govern, Identify, Protect, Detect, Respond, Recover) → Categories → Subcategories
  • Best for: General-purpose program baseline; widely accepted as the US de-facto standard; regulatory "reasonableness" reference
  • Limitation: High-level outcomes, not prescriptive controls. Organizations must interpret what "reasonable" implementation looks like
  • SCF Coverage: 100% of NIST CSF subcategories mapped to SCF controls

Deep Dive: NIST CSF 2.0 →

NIST SP 800-53

  • Description: Security and Privacy Controls for Federal Systems
  • Cost: Free
  • Voluntary: Federal / High-Rigor
  • Created by: NIST: the most comprehensive US government control catalog
  • Structure: 20 control families; 1,000+ controls and enhancements; baseline variants (Low/Moderate/High)
  • Best for: Federal agencies (required by FISMA); FedRAMP cloud authorization; high-security commercial environments
  • Limitation: Highly prescriptive and comprehensive. Significant implementation overhead for non-federal organizations
  • SCF Coverage: Full NIST SP 800-53 Rev 5 mapped to SCF via STRM

Deep Dive: NIST SP 800-53 →

ISO 27001 / 27002

  • Description: International Standard for Information Security Management
  • Cost: Paid Standard
  • Certifiable: Yes
  • Applicable Sectors: Global
  • Created by: ISO / IEC: international standards body
  • Structure: ISMS requirements (ISO 27001) + implementation guidance (ISO 27002); 93 controls in 4 themes; formal certification via accredited body
  • Best for: Organizations selling to EU enterprise customers; international supply chains; formal third-party certification needs
  • Limitation: Certification requires paid auditor; standard text requires purchase; less prescriptive than NIST
  • SCF Coverage: Full ISO 27001:2022 Annex A mapped to SCF controls

Deep Dive: ISO 27001/2 →

CIS Controls v8

  • Description: Center for Internet Security Critical Security Controls
  • Cost: Free
  • Prioritized: Yes
  • Practical: Yes
  • Created by: Center for Internet Security (CIS): community-developed
  • Structure: 18 control groups; 153 safeguards; three Implementation Groups (IG1/2/3) based on organization size and risk
  • Best for: Practical, prioritized starting point; SMBs using IG1; technically-oriented security teams; quick wins identification
  • Limitation: Not comprehensive enough for regulatory compliance on its own; limited privacy and GRC coverage
  • SCF Coverage: All CIS v8 safeguards mapped to SCF controls

Deep Dive: CIS Controls →

SOC 2

  • Description: Service Organization Control 2: Trust Services Criteria
  • Audit Required: Yes
  • Applicable Sectors: B2B / SaaS
  • Created by: AICPA (American Institute of CPAs)
  • Structure: Trust Service Criteria: Security (required) + Availability, Confidentiality, Privacy, Processing Integrity (optional); Type I or Type II reports
  • Best for: SaaS and cloud companies; B2B vendor assurance; customer security questionnaire replacement
  • Limitation: Requires licensed CPA firm audit; significant cost; report confidential and not publicly shareable without NDA
  • SCF Coverage: All SOC 2 Trust Service Criteria mapped to SCF controls

Deep Dive: SOC 2 →

PCI DSS v4.0

  • Description: Payment Card Industry Data Security Standard
  • Cost: Free (Standard)
  • Audit Often Required: Yes
  • Applicable Sectors: Payments
  • Created by: PCI Security Standards Council (Visa, Mastercard, Amex, Discover, JCB)
  • Structure: 12 requirements; 300+ sub-requirements; Cardholder Data Environment (CDE) scoping; SAQ or QSA assessment
  • Best for: Any organization accepting, processing, storing, or transmitting payment card data, contractually required by card brands
  • Limitation: Highly prescriptive; technically complex CDE scoping; not a general security framework with a narrow payment card focus
  • SCF Coverage: All PCI DSS v4.0 requirements mapped to SCF controls

Deep Dive: PCI DSS →

HITRUST CSF

  • Description: Health Information Trust Alliance Common Security Framework
  • Subscription Required: Yes
  • Applicable Sectors: Healthcare
  • Certifiable: Yes
  • Created by: HITRUST Alliance: a healthcare industry consortium
  • Structure: 19 domains; control selection based on risk factors; three assurance levels (e1 / i1 / r2); requires HITRUST-authorized assessor
  • Best for: Healthcare vendors and covered entities; organizations replacing multiple HIPAA questionnaires with one certification
  • Limitation: Significant cost (licensing + assessor); complex scoping; primarily US healthcare focus
  • SCF Coverage: The SCF does not map to HITRUST CSF

Deep Dive: HITRUST →

Major Frameworks: Feature Comparison

How the most common cybersecurity frameworks compare across key features: cost, certifiability, privacy coverage, GRC breadth, and SCF mapping status.

Framework Free? Certifiable? Privacy Coverage? GRC Coverage? MCR-Tagged? Mapped in SCF?
SCF ✓ ✓ SCF-CAP ✓ Full ✓ Full ✓ Yes ✓ It IS the map
NIST CSF 2.0 ✓ — No Partial — No ✓ Yes
NIST SP 800-53 ✓ — FedRAMP ✓ Yes — No ✓ Yes
ISO 27001/2 — Paid ✓ Yes ISO 27701 Partial — No
CIS Controls v8 ✓ — No Partial — No ✓ Yes
SOC 2 — Paid Audit ✓ Yes Optional Partial — No
PCI DSS v4 Std Free / Audit Paid ✓ QSA/SAQ — No — No — No ✓ Yes

Controls are your security, compliance & resilience program - A control is the power to influence or direct behaviors and the course of events.