Common Cybersecurity Frameworks
Cybersecurity frameworks are voluntary best-practice guidance, not laws. But they define the industry standard for "reasonable" security and are increasingly required by contract, regulation, or as a condition of doing business. Here is what the major frameworks actually are, what they require, and how the SCF CCF™ supersedes them all.
Major Cybersecurity Frameworks
The Most Widely Used Cybersecurity Frameworks
These are the frameworks most commonly required by contracts, mentioned in regulatory guidance, and used by security teams as program baselines. All are mapped in the SCF CCF™.
NIST CSF 2.0
- Description: NIST Cybersecurity Framework, Version 2.0 (2024)
- Cost: Free
- Voluntary: Yes
- Applicable Sectors: All Sectors
- Created by: NIST (National Institute of Standards and Technology)
- Structure: 6 Functions (Govern, Identify, Protect, Detect, Respond, Recover) → Categories → Subcategories
- Best for: General-purpose program baseline; widely accepted as the US de-facto standard; regulatory "reasonableness" reference
- Limitation: High-level outcomes, not prescriptive controls. Organizations must interpret what "reasonable" implementation looks like
- SCF Coverage: 100% of NIST CSF subcategories mapped to SCF controls
NIST SP 800-53
- Description: Security and Privacy Controls for Federal Systems
- Cost: Free
- Voluntary: Federal / High-Rigor
- Created by: NIST: the most comprehensive US government control catalog
- Structure: 20 control families; 1,000+ controls and enhancements; baseline variants (Low/Moderate/High)
- Best for: Federal agencies (required by FISMA); FedRAMP cloud authorization; high-security commercial environments
- Limitation: Highly prescriptive and comprehensive. Significant implementation overhead for non-federal organizations
- SCF Coverage: Full NIST SP 800-53 Rev 5 mapped to SCF via STRM
ISO 27001 / 27002
- Description: International Standard for Information Security Management
- Cost: Paid Standard
- Certifiable: Yes
- Applicable Sectors: Global
- Created by: ISO / IEC: international standards body
- Structure: ISMS requirements (ISO 27001) + implementation guidance (ISO 27002); 93 controls in 4 themes; formal certification via accredited body
- Best for: Organizations selling to EU enterprise customers; international supply chains; formal third-party certification needs
- Limitation: Certification requires paid auditor; standard text requires purchase; less prescriptive than NIST
- SCF Coverage: Full ISO 27001:2022 Annex A mapped to SCF controls
CIS Controls v8
- Description: Center for Internet Security Critical Security Controls
- Cost: Free
- Prioritized: Yes
- Practical: Yes
- Created by: Center for Internet Security (CIS): community-developed
- Structure: 18 control groups; 153 safeguards; three Implementation Groups (IG1/2/3) based on organization size and risk
- Best for: Practical, prioritized starting point; SMBs using IG1; technically-oriented security teams; quick wins identification
- Limitation: Not comprehensive enough for regulatory compliance on its own; limited privacy and GRC coverage
- SCF Coverage: All CIS v8 safeguards mapped to SCF controls
SOC 2
- Description: Service Organization Control 2: Trust Services Criteria
- Audit Required: Yes
- Applicable Sectors: B2B / SaaS
- Created by: AICPA (American Institute of CPAs)
- Structure: Trust Service Criteria: Security (required) + Availability, Confidentiality, Privacy, Processing Integrity (optional); Type I or Type II reports
- Best for: SaaS and cloud companies; B2B vendor assurance; customer security questionnaire replacement
- Limitation: Requires licensed CPA firm audit; significant cost; report confidential and not publicly shareable without NDA
- SCF Coverage: All SOC 2 Trust Service Criteria mapped to SCF controls
PCI DSS v4.0
- Description: Payment Card Industry Data Security Standard
- Cost: Free (Standard)
- Audit Often Required: Yes
- Applicable Sectors: Payments
- Created by: PCI Security Standards Council (Visa, Mastercard, Amex, Discover, JCB)
- Structure: 12 requirements; 300+ sub-requirements; Cardholder Data Environment (CDE) scoping; SAQ or QSA assessment
- Best for: Any organization accepting, processing, storing, or transmitting payment card data, contractually required by card brands
- Limitation: Highly prescriptive; technically complex CDE scoping; not a general security framework with a narrow payment card focus
- SCF Coverage: All PCI DSS v4.0 requirements mapped to SCF controls
HITRUST CSF
- Description: Health Information Trust Alliance Common Security Framework
- Subscription Required: Yes
- Applicable Sectors: Healthcare
- Certifiable: Yes
- Created by: HITRUST Alliance: a healthcare industry consortium
- Structure: 19 domains; control selection based on risk factors; three assurance levels (e1 / i1 / r2); requires HITRUST-authorized assessor
- Best for: Healthcare vendors and covered entities; organizations replacing multiple HIPAA questionnaires with one certification
- Limitation: Significant cost (licensing + assessor); complex scoping; primarily US healthcare focus
- SCF Coverage: The SCF does not map to HITRUST CSF
Major Frameworks: Feature Comparison
How the most common cybersecurity frameworks compare across key features: cost, certifiability, privacy coverage, GRC breadth, and SCF mapping status.
| Framework | Free? | Certifiable? | Privacy Coverage? | GRC Coverage? | MCR-Tagged? | Mapped in SCF? |
|---|---|---|---|---|---|---|
| SCF | ✓ | ✓ SCF-CAP | ✓ Full | ✓ Full | ✓ Yes | ✓ It IS the map |
| NIST CSF 2.0 | ✓ | — | No | Partial | — No | ✓ Yes |
| NIST SP 800-53 | ✓ | — | FedRAMP | ✓ Yes | — No | ✓ Yes |
| ISO 27001/2 | — | Paid | ✓ Yes | ISO 27701 | Partial | — No |
| CIS Controls v8 | ✓ | — | No | Partial | — No | ✓ Yes |
| SOC 2 | — | Paid Audit | ✓ Yes | Optional | Partial | — No |
| PCI DSS v4 | Std Free / Audit Paid | ✓ QSA/SAQ | — No | — No | — No | ✓ Yes |
Controls are your security, compliance & resilience program - A control is the power to influence or direct behaviors and the course of events.