# Set Theory Relationship Mapping (STRM)

Starting with release 2024.1, the SCF leverages NIST IR 8477 Set Theory Relationship Mapping for crosswalk mapping. This is the US Government's gold standard for evaluating cybersecurity and data privacy laws, regulations and frameworks.

5

Relationship Types

200+

LRF Mapped

NIST IR 8477

Gold Standard

EDC

Expert-Derived Content

[Download the SCF](/content/free-content/scf-download/index.html) [Learn More About the SCF](/content/start-here/index.html) [STRM Overview](https://content.securecontrolsframework.com/pdf/scf-set-theory-relationship-mapping.pdf)

NIST IR 8477

## The Gold Standard for Crosswalk Mapping

[NIST IR 8477](https://csrc.nist.gov/pubs/ir/8477/final) provides the definitive practice for crosswalk mapping with no technology needed. It can be performed with a pencil and piece of paper.

Children learn the process of diagramming sentences in grade school (e.g., the Reed–Kellogg model) with pencil and paper. This same process of graphically identifying the relationships between elements forms the basis of STRM. What NIST IR 8477 does is formalize this with Set Theory mathematics to produce rigorous, defensible, and IP-protected crosswalk mappings.

STRM is part of NIST’s broader [NIST OLIR Program](/content/start-here/set-theory-relationship-mapping-strm#https://csrc.nist.gov/projects/olir/index.html), an effort to facilitate Subject Matter Experts in defining standardized Online Informative References between elements of their creation and NIST publications.

You can click on the image to the side to see a PDF version of how the SCF is utilizing STRM, as well as an example for what that looks like with a few NIST CSF 2.0 controls:

### Purchase STRM Excel Bundles

The SCF offers editable Excel versions of all STRM mappings. The bundle of Excel versions is $25 (access to redownload is availabe for 30 days from date of purchase).

[BUY STRM BUNDLE](https://store.securecontrolsframework.com/cart?name=STRM-Bundle&code=STRM&category=STRM&price=25.00)

STRM Methodology

## The 5 STRM Relationship Types

Every crosswalk mapping in the SCF uses exactly one of these five mathematically-defined relationship types, ensuring precision and consistency across all 200+ mapped LRF.

**⊂**

#### Subset Of

The LRF requirement is fully contained within the SCF control. The SCF control is broader in scope and coverage.

**∩**

#### Intersects With

The LRF requirement and SCF control share partial overlap. Neither is fully contained within the other.

**=**

#### Equal To

The LRF requirement and SCF control are semantically equivalent. They address the same concept at the same scope.

**⊃**

#### Superset Of

The SCF control is contained within the LRF requirement. The LRF requirement is broader in scope and coverage.

**Ø**

#### No Relationship

The LRF requirement and SCF control have no meaningful semantic overlap. No mapping is established.

Relationship Strength (1–10)

Relationship Strength (1–10): Each mapping also receives a numeric strength rating. A rating of 1 indicates a nominal relationship, 5 indicates moderately strong, and 10 indicates the strongest relationship, typically reserved for "Equal To" or where the LRF requirement is a "Subset Of" the SCF control.

Methodology Advantage

## Expert-Derived Content (EDC) vs. Natural Language Processing (NLP)

The SCF exclusively uses human subject-matter experts to perform STRM crosswalk mapping. This is a deliberate choice with significant IP, legal and quality implications.

#### SCF: Expert-Derived Content (EDC)

The SCF leverages human SMEs to perform STRM mapping. This produces content that is:

- Copyright-protected as original work by human creators
- Patent-eligible under the “mental steps” doctrine
- Defensible through documented expert judgment
- Consistent with NIST IR 8477 gold standard practices

#### Other Vendors: Natural Language Processing (NLP)

AI/NLP-based crosswalk solutions face significant IP limitations:

- AI-generated content is not copyright-protectable (no human creator)
- Potentially free to copy under current US copyright rulings
- Patent claims may be invalid under the 2014 Supreme Court “mental steps” doctrine
- Quality depends on training data rather than professional expertise

Why it matters

The SCF's EDC approach means its crosswalk mappings are both higher-quality and legally protected intellectual property, which is exactly how NIST IR 8477 itself was designed to work.

SCF Implementation

## How the SCF Utilizes STRM

The SCF applies STRM to every one of its 200+ mapped laws, regulations and frameworks. Each mapping documents the precise set-theoretic relationship between every LRF requirement and the corresponding SCF control.

### Focal Document Element (FDE)

Each LRF requirement is defined as a Focal Document Element with a unique identifier. Without a unique FDE value, no granular mapping is possible because there is nothing to map to.

### SCF Control Mapping

Each FDE is mapped to the most appropriate SCF control with a documented relationship type (Subset Of, Intersects With, Equal To, Superset Of, or No Relationship) and a strength score of 1–10.

### Multi-Framework Compliance

Because all LRF are mapped to common SCF controls using STRM, a single SCF control can simultaneously satisfy requirements across dozens of laws, regulations and frameworks. This enables true multi-framework compliance efficiency.

Available STRMs

## Published STRM Mappings

Excel versions of the STRM mappings are available for purchase at the SCF Store. The following STRM mappings are currently published:

[ALL](/content/start-here/set-theory-relationship-mapping-strm#w-tabs-0-data-w-pane-0/index.html) [GENERAL](/content/start-here/set-theory-relationship-mapping-strm#w-tabs-0-data-w-pane-1/index.html) [USA](/content/start-here/set-theory-relationship-mapping-strm#w-tabs-0-data-w-pane-2/index.html) [EMEA](/content/start-here/set-theory-relationship-mapping-strm#w-tabs-0-data-w-pane-3/index.html) [APAC](/content/start-here/set-theory-relationship-mapping-strm#w-tabs-0-data-w-pane-4/index.html) [AMERICAS](/content/start-here/set-theory-relationship-mapping-strm#w-tabs-0-data-w-pane-5/index.html)

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

Americas

✓ STRM

Canada

Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-americas-can-itsp-10-171-2025.pdf)

Americas

✓ STRM

Canada

Canada - OSFI B-13 (2022)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-americas-can-osfi-b13-2022.pdf)

APAC

✓ STRM

New Zealand

New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-nzl-hisf-suppliers-2023.pdf)

APAC

✓ STRM

New Zealand

New Zealand - HISF MicroSmall (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-nzl-hisf-microsmall-2023.pdf)

APAC

✓ STRM

New Zealand

New Zealand - HISF MLHSP (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-nzl-hisf-mlhsp-2023.pdf)

APAC

✓ STRM

India

India - SEBI Cybersecurity and Cyber Resilience Framework (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-ind-sebi-2024.pdf)

APAC

✓ STRM

India

India Digital Personal Data Protection Act (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-ind-dpdpa-2023.pdf)

APAC

✓ STRM

China

China - Cybersecurity Law of the People's Republic of China (2017)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-chn-cybersecurity-law-2017.pdf)

APAC

✓ STRM

Australia

Australia - Information Security Manual (ISM) (June 2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-aus-ism-2024-june.pdf)

APAC

✓ STRM

Australia

Australia -Essential Eight maturity model and ISM mapping (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-aus-essential-8-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L3

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-l3-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-l2-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-l0-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-l1-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-2024.pdf)

EMEA

✓ STRM

Spain

Royal Decree 311/2022, of May 3, which regulates the National Security Scheme (BOE-A-2022-7191)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-esp-boe-a-2022-7191.pdf)

EMEA

✓ STRM

United Kingdom

UK - Cyber Assessment Framework (CAF) v4.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-caf-4-0.pdf)

EMEA

✓ STRM

UAE

UAE - National Information Assurance Framework (NIAF) (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-uae-niaf-2023.pdf)

EMEA

✓ STRM

Saudi Arabia

Saudi Arabia - Personal Data Protection Law (PDPL) (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-sau-pdpl-2023.pdf)

USA

✓ STRM

State

Colorado Privacy Act (2021)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-co-privacy-act-2021.pdf)

EMEA

✓ STRM

Saudi Arabia

Saudi Arabia - Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-sau-cgiot-2024.pdf)

EMEA

✓ STRM

EU

European Union Agency for Cybersecurity NIS2 (Directive (EU) 2022/2555)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-nis2-2022.pdf)

EMEA

✓ STRM

EU

European Union Agency for Cybersecurity NIS2 Annex (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-nis2-annex-2024.pdf)

EMEA

✓ STRM

EU

European Union General Data Protection Regulation (2016)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-gdpr-2016.pdf)

EMEA

✓ STRM

EU

Digital Operational Resilience Act (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-dora-2023.pdf)

EMEA

✓ STRM

EU

European Union Cyber Resilience Act - Annexes (2022)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-cyber-resilience-act-annexes-2022.pdf)

EMEA

✓ STRM

EU

European Union Cyber Resilience Act (2022)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-cyber-resilience-act-2022.pdf)

EMEA

✓ STRM

EU

European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-ai-act-2024.pdf)

USA

✓ STRM

State

Virginia Consumer Data Protection Act (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-va-cdpa-2023.pdf)

USA

✓ STRM

State

Vermont Data Broker Registration Act (Act 171 of 2018)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-vt-act-171-2018.pdf)

USA

✓ STRM

State

Texas Risk & Authorization Management Program 2.0 - Level 2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-txramp-2-0-level-2.pdf)

USA

✓ STRM

State

Texas Safe Harbor Law (SB2610) (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-sb2610-2025.pdf)

USA

✓ STRM

State

Texas Risk & Authorization Management Program 2.0 - Level 1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-txramp-2-0-level-1.pdf)

USA

✓ STRM

State

Texas SB820 (2019)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-sb820-2019.pdf)

USA

✓ STRM

State

Tennessee Information Protection Act (TIPA) (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tn-tipa-2025.pdf)

USA

✓ STRM

State

Texas Identity Theft Enforcement and Protection Act (BC521) (2009)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-bc521-2009.pdf)

USA

✓ STRM

State

Texas DIR Security Control Standards Catalog v2.2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-dir-security-control-standards-catalog-2-2.pdf)

USA

✓ STRM

State

Texas Consumer Data Protection Act (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-cdpa-2025.pdf)

USA

✓ STRM

State

New York Department of Financial Services 23NYCRR Part 500 (2023 Amendment 2)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ny-dfs-23-nycrr500-2023-amd2.pdf)

USA

✓ STRM

State

Oregon Consumer Privacy Act (SB 619) (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-or-cpa-2023.pdf)

USA

✓ STRM

State

Oregon Consumer Information Protection Act (ORS 646A) (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-or-ors-646a-2025.pdf)

USA

✓ STRM

State

New York SHIELD Act (SB S5575B) (2019)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ny-shield-act-2019.pdf)

USA

✓ STRM

State

Nevada SB220 (2019)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-nv-sb220-2019.pdf)

USA

✓ STRM

State

Nevada Privacy Law (2023)- CHAPTER 603A - SECURITY AND PRIVACY OF PERSONAL INFORMATION

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-nv-privacy-law-2023.pdf)

USA

✓ STRM

State

Nevada Operation of Gaming Establishments - Regulation 5.260 (Cybersecurity)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-nv-regulation-5-2024.pdf)

USA

✓ STRM

State

Massachusetts 201 CMR 17.00 (2008)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ma-201-cmr-17-2008.pdf)

USA

✓ STRM

State

Illinois Personal Information Protection Act (PIPA) (2006)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-il-pipa-2006.pdf)

USA

✓ STRM

State

Illinois Identity Protection Act (IPA) (2009)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-il-ipa-2009.pdf)

USA

✓ STRM

State

Illinois Biometric Information Privacy Act (BIPA) (2008)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-il-bipa-2008.pdf)

USA

✓ STRM

State

California SB1386 (2002)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ca-sb1386-2002.pdf)

USA

✓ STRM

State

California SB327 (2018)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ca-sb327-2018.pdf)

USA

✓ STRM

State

Alaska Personal Information Protection Act (PIPA) (2009)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ak-pipa-2009.pdf)

USA

✓ STRM

State

California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ca-ccpa-cpra-2026.pdf)

USA

✓ STRM

Federal

Transportation Security Administration Security Directive 1580/82-2022-01 - Rail Cybersecurity Mitigation Actions and Testing

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-tsa-security-directive-1580-82-2022-01.pdf)

USA

✓ STRM

Federal

Sarbanes Oxley Act (2002)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-sox-2002.pdf)

USA

✓ STRM

Federal

SEC Cybersecurity Rule (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-sec-cybersecurity-rule-2023.pdf)

USA

✓ STRM

Federal

North American Electric Reliability Corporation Critical Infrastructure Protection (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-nerc-cip-2024.pdf)

USA

✓ STRM

Federal

National Industrial Security Program Operating Manual (2020)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-nispom-2020.pdf)

USA

✓ STRM

Federal

Safeguarding of Naval Nuclear Propulsion Information (NNPI) (2010)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-safeguarding-nnpi-2010.pdf)

USA

✓ STRM

Federal

US Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-cms-marse-2-0.pdf)

USA

✓ STRM

Federal

Internal Revenue Service 1075 (2021)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-irs-1075-2021.pdf)

USA

✓ STRM

Federal

HIPAA Security Rule (2013)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-hipaa-security-rule-2013.pdf)

USA

✓ STRM

Federal

HIPAA Administrative Simplification (2013)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-hipaa-simplification-2013.pdf)

USA

✓ STRM

Federal

Gramm Leach Bliley Act - CFR 314 (Dec 2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-glba-cfr-314-2023.pdf)

USA

✓ STRM

Federal

HHS § 155.260 - Privacy and Security of Personally Identifiable Information (2016)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-hhs-45-cfr-155-260-2016.pdf)

USA

✓ STRM

Federal

Federal Trade Commission (FTC) Act

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-ftc-act.pdf)

USA

✓ STRM

Federal

US Fair Information Practice Principles (FIPPs) (1973)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-omb-fipps-1973.pdf)

USA

✓ STRM

Federal

Financial Industry Regulatory Authority (FINRA) Cybersecurity Rules

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-sro-finra.pdf)

USA

✓ STRM

Federal

Family Educational Rights and Privacy Act (FERPA) (2010)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-ferpa-2010.pdf)

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Li-SAAS Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-gsa-fedramp-5-li-saas.pdf)

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - High Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-gsa-fedramp-5-high.pdf)

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Moderate Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-gsa-fedramp-5-mod.pdf)

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Low Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-gsa-fedramp-5-low.pdf)

USA

✓ STRM

Federal

Food & Drug Administration 21 CFR Part 11 (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-fda-21-cfr-part-11-2025.pdf)

USA

✓ STRM

Federal

Farm Credit Administration Cyber Risk Management (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-sro-fca-crm-2023.pdf)

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-27 - Prohibition on a ByteDance Covered Application

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-far-52-204-27.pdf)

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-25 (NDAA Section 889) - Prohibition on Contracting With Entities Using Certain Telecommunications and Video Surveillance Services or Equipment

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-far-52-204-25.pdf)

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-21 - Basic Safeguarding of Covered Contractor Information Systems

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-far-52-204-21.pdf)

USA

✓ STRM

Federal

Fair & Accurate Credit Transactions Act (FACTA) & Fair Credit Reporting Act (FCRA) (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-facta-fcra-2023.pdf)

USA

✓ STRM

Federal

Executive Order 14028 - Improving the Nation's Cybersecurity

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-eo-14028.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Zero Trust Reference Architecture v2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-zta-reference-architecture-2-0.pdf)

USA

✓ STRM

Federal

Defense Federal Acquisition Regulation Supplement 252.204-7012

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-dfars-252-204-7012.pdf)

USA

✓ STRM

Federal

Data Privacy Framework (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-doc-data-privacy-framework-2023.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Zero Trust Execution Roadmap v1.1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-zt-roadmap-1-1.pdf)

USA

✓ STRM

Federal

US Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-fbi-cjis-6-0.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 3

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cmmc-2-level-3.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cmmc-2-level-2.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 1 Assessment Objectives

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cmmc-2-level-1-aos.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cmmc-2-level-1.pdf)

USA

✓ STRM

Federal

Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-doe-c2m2-2-1.pdf)

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals 2.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dhs-cisa-cpg-2-0.pdf)

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dhs-cisa-tic-3-0.pdf)

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dhs-cisa-ssdaf-2024.pdf)

USA

✓ STRM

Federal

Children's Online Privacy Protection Act (COPPA) (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-coppa-2024.pdf)

USA

✓ STRM

Federal

US Computer Emergency Response Team Resilience Management Model Version 1.2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cert-rmm-1-2.pdf)

General

✓ STRM

United Nations

United Nations Regulation No. 155 - Cyber security and cyber security management system (2021)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-un-155-2021.pdf)

General

✓ STRM

United Nations

United Nations Economic Commission for Europe - Working Party on Automated/autonomous and Connected Vehicles -Proposal for a new UN Regulation on uniform provisions concerning the approval of vehicles with regards to cyber security and cyber security manag

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-un-ece-wp-29-2020.pdf)

General

✓ STRM

UL

UL 2900-2-2 Ed. 1-2016 - Outline of Investigation for Software Cybersecurity for Network-Connectable Products, Part 2-2: Particular Requirements for Industrial Control Systems

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-ul-2900-2-2-2016.pdf)

General

✓ STRM

UL

UL 2900-1- Software Cybersecurity for Network-Connectable Products, Part 1: General Requirements (2017)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-ul-2900-1-2017.pdf)

General

✓ STRM

TISAX

Trusted Information Security Assessment Exchange (TISAX) 6.0.3

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-tisax-6-0-3.pdf)

General

✓ STRM

SWIFT

Society for Worldwide Interbank Financial Telecommunication Customer Security Controls Framework 2025

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-swift-cscf-2025.pdf)

General

✓ STRM

SPARTA

Space Attack Research & Tactic Analysis (SPARTA) Countermeasures

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-sparta.pdf)

General

✓ STRM

SCF

Secure Controls Framework (SCF) Data Privacy Management Principles (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-scf-dpmp-2025.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire P2PE

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-p2pe.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire D Service Provider

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-d-service-provider.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire D Merchant

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-d-merchant.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire C-VT

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-c-vt.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire B-IP

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-b-ip.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire C

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-c.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire B

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-b.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire A-EP

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-a-ep.pdf)

General

✓ STRM

OWASP

Open Worldwide Application Security Project (OWASP) Top 10 (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-owasp-top-10-2025.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire A

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-a.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.01

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1.pdf)

General

✓ STRM

OECD

Organisation for Economic Co-operation and Development Privacy Principles

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-oecd-privacy-principles-2010.pdf)

General

✓ STRM

NIST

NIST Cybersecurity Framework v2.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-csf-2-0.pdf)

General

✓ STRM

NIST

NIST SP 800-218 - Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-218.pdf)

General

✓ STRM

NIST

NIST SP 800-207 - Zero Trust Architecture

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-207.pdf)

General

✓ STRM

NIST

NIST SP 800-172 - Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-172.pdf)

General

✓ STRM

NIST

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-171a.pdf)

General

✓ STRM

NIST

NIST SP 800-171A R3 - Assessing Security Requirements for Controlled Unclassified Information

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-171a-r3.pdf)

General

✓ STRM

NIST

NIST SP 800-171 R2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-171-r2.pdf)

General

✓ STRM

NIST

NIST SP 800-171 R3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-171-r3.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 3 Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-level-3.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 2 Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-level-2.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 1 Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-level-1.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Flow Down Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-flowdown.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - C-SCRM Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-cscrm.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1.pdf)

General

✓ STRM

NIST

NIST SP 800-160 Volume 2, Revision 1 - Developing Cyber-Resilient Systems: A Systems Security Engineering Approach

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-160-vol-2-r1.pdf)

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - High OT Overlay

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-82-r3-high.pdf)

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Moderate OT Overlay

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-82-r3-mod.pdf)

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-82-r3-low.pdf)

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-82-r3-low.pdf)

General

✓ STRM

NIST

NIST SP 800-66 R2 - Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-66-r2.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - High Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2-high.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Moderate Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2-mod.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Low Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2-low.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Privacy Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2-privacy.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2.pdf)

General

✓ STRM

NIST

NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-39.pdf)

General

✓ STRM

NIST

NIST SP 800-37 R2 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-37-r2.pdf)

General

✓ STRM

NIST

NIST Privacy Framework v1.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-privacy-framework-1-0.pdf)

General

✓ STRM

NIST

NIST AI 600-1 - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-600-1-gen-ai-profile.pdf)

General

✓ STRM

NIST

NIST AI 100-1 - Artificial Intelligence Risk Management Framework (AI RMF 1.0)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-100-1-ai-rmf.pdf)

General

✓ STRM

NAIC

National Association of Insurance Commissioners Insurance Data Security Model Law (MDL-668) (2017)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-naic-insurance-data-security-model-law-668-2017.pdf)

General

✓ STRM

MPA

Motion Picture Association (MPA) Content Security Best Practices Common Guidelines v5.3.1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-mpa-csbp-5-3-1.pdf)

General

✓ STRM

MITRE

MITRE Adversarial Tactics, Techniques, and Common Knowledge - NIST 800-53 mappings

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-mitre-att&ck-16-1.pdf)

General

✓ STRM

ISO

ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-42001-2023.pdf)

General

✓ STRM

ISO

IEC 31010:2019 - Risk management - Risk assessment techniques

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-31010-2009.pdf)

General

✓ STRM

ISO

ISO/IEC 29100:2024 - Information technology - Security techniques - Privacy framework

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-29100-2024.pdf)

General

✓ STRM

ISO

ISO 31000:2018 - Risk management - Guidelines

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-31000-2018.pdf)

General

✓ STRM

ISO

ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27701-2025.pdf)

General

✓ STRM

ISO

ISO/IEC 27018:2025 - Information security, cybersecurity and privacy protection - Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27018-2025.pdf)

General

✓ STRM

ISO

ISO/IEC 27017:2015 - Information technology - Security techniques -Code of practice for information security controls based on ISO/IEC 27002 for cloud services

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27017-2015.pdf)

General

✓ STRM

ISO

ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27002-2022.pdf)

General

✓ STRM

ISO

ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27001-2022.pdf)

General

✓ STRM

ISO

ISO 22301:2019 - Security and resilience - Business continuity management systems - Requirements

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-22301-2019.pdf)

General

✓ STRM

IEC

ISO/SAE 21434:2021 - Road vehicles - Cybersecurity engineering

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-21434-2021.pdf)

General

✓ STRM

IMO

International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-imo-maritime-cyber-risk-management-2025.pdf)

General

✓ STRM

IEC

International Electrotechnical Commission 62443-4-1:2018 - Security for industrial automation and control systems - Part 4-1: Secure product development lifecycle requirements

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-62443-4-1-2018.pdf)

General

✓ STRM

IEC

International Electrotechnical Commission 62443-4-2 Ed. 1.0 b:2019 - Security for industrial automation and control systems - Part 4-2: Technical security requirements for IACS components

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-62443-4-2-2019.pdf)

General

✓ STRM

IEC

International Electrotechnical Commission 62443-3-3:2013 - Industrial communication networks - Network and system security - Part 3-3: System security requirements and security levels

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-62443-3-3-2013.pdf)

General

✓ STRM

IEC

International Electrotechnical Commission 62443-2-1:2024 - Security for industrial automation and control systems - Part 2-1: Security program requirements for IACS asset owners

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-62443-2-1-2024.pdf)

General

✓ STRM

IEC

International Electrotechnical Commission Technical Report 60601-4-5:2021 - Medical electrical equipment - Part 4-5: Guidance and interpretation - Safety-related technical security specifications

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-tr-60601-4-5-2021.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - High

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-high.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Moderate

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-mod.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Core Controls

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-core.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Low+

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-low-plus.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Low

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-low.pdf)

General

✓ STRM

CR

Cyber Resilience Capability Maturity Model (CR-CMM) (2026)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cr-cmm-2026.pdf)

General

✓ STRM

COSO

Committee of Sponsoring Organizations (COSO) (2013)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-coso-2013.pdf)

General

✓ STRM

CSA

Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-csa-cmm-4-1-0.pdf)

General

✓ STRM

ISACA

Control Objectives for Information and Related Technologies (COBIT) (2019)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cobit-2019.pdf)

General

✓ STRM

CSA

Cloud Security Alliance (CSA) Internet of Things Security Controls Framework v2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-csa-iot-2.pdf)

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG3

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cis-csc-8-1-ig3.pdf)

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cis-csc-8-1-ig2.pdf)

General

✓ STRM

APEC

Asia-Pacific Economic Cooperation (APEC) Privacy Framework (2015)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-apec-privacy-framework-2015.pdf)

General

✓ STRM

BSI

Bundesamt für Sicherheit in der Informationstechnik (BSI) - Standard 200-1 (v1.0)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-bsi-200-1-1-0.pdf)

General

✓ STRM

AICPA

American Institute of Certified Public Accountants (AICPA) Trust Services Criteria (2017)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-aicpa-tsc-2017.pdf)

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cis-csc-8-1.pdf)

General

✓ STRM

AICPA

American Institute of Certified Public Accountants (AICPA) Privacy Management Framework (PMF) (2020)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-aicpa-pmf-2020.pdf)

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cis-csc-8-1-ig1.pdf)

[Previous](/content/start-here/set-theory-relationship-mapping-strm?64dec907_page=8/index.html) [Next](/content/start-here/set-theory-relationship-mapping-strm?64dec907_page=2/index.html)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

General

✓ STRM

United Nations

United Nations Regulation No. 155 - Cyber security and cyber security management system (2021)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-un-155-2021.pdf)

General

✓ STRM

United Nations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-un-ece-wp-29-2020.pdf)

General

✓ STRM

UL

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-ul-2900-2-2-2016.pdf)

General

✓ STRM

UL

UL 2900-1- Software Cybersecurity for Network-Connectable Products, Part 1: General Requirements (2017)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-ul-2900-1-2017.pdf)

General

✓ STRM

TISAX

Trusted Information Security Assessment Exchange (TISAX) 6.0.3

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-tisax-6-0-3.pdf)

General

✓ STRM

SWIFT

Society for Worldwide Interbank Financial Telecommunication Customer Security Controls Framework 2025

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-swift-cscf-2025.pdf)

General

✓ STRM

SPARTA

Space Attack Research & Tactic Analysis (SPARTA) Countermeasures

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-sparta.pdf)

General

✓ STRM

SCF

Secure Controls Framework (SCF) Data Privacy Management Principles (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-scf-dpmp-2025.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire P2PE

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-p2pe.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire D Service Provider

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-d-service-provider.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire D Merchant

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-d-merchant.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire C-VT

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-c-vt.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire B-IP

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-b-ip.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire C

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-c.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire B

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-b.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire A-EP

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-a-ep.pdf)

General

✓ STRM

OWASP

Open Worldwide Application Security Project (OWASP) Top 10 (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-owasp-top-10-2025.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.0.1 - Self-Assessment Questionnaire A

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1-saq-a.pdf)

General

✓ STRM

PCI SSC

Payment Card Industry Data Security Standard v4.01

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-pci-dss-4-0-1.pdf)

General

✓ STRM

OECD

Organisation for Economic Co-operation and Development Privacy Principles

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-oecd-privacy-principles-2010.pdf)

General

✓ STRM

NIST

NIST Cybersecurity Framework v2.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-csf-2-0.pdf)

General

✓ STRM

NIST

NIST SP 800-218 - Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-218.pdf)

General

✓ STRM

NIST

NIST SP 800-207 - Zero Trust Architecture

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-207.pdf)

General

✓ STRM

NIST

NIST SP 800-172 - Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-172.pdf)

General

✓ STRM

NIST

NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-171a.pdf)

General

✓ STRM

NIST

NIST SP 800-171A R3 - Assessing Security Requirements for Controlled Unclassified Information

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-171a-r3.pdf)

General

✓ STRM

NIST

NIST SP 800-171 R2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-171-r2.pdf)

General

✓ STRM

NIST

NIST SP 800-171 R3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-171-r3.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 3 Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-level-3.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 2 Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-level-2.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Level 1 Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-level-1.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - Flow Down Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-flowdown.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations - C-SCRM Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1-cscrm.pdf)

General

✓ STRM

NIST

NIST SP 800-161 R1 UDP1 - Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-161-r1.pdf)

General

✓ STRM

NIST

NIST SP 800-160 Volume 2, Revision 1 - Developing Cyber-Resilient Systems: A Systems Security Engineering Approach

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-160-vol-2-r1.pdf)

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - High OT Overlay

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-82-r3-high.pdf)

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Moderate OT Overlay

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-82-r3-mod.pdf)

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-82-r3-low.pdf)

General

✓ STRM

NIST

NIST SP 800-82 R3 - Guide to Operational Technology (OT) Security - Low OT Overlay

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-82-r3-low.pdf)

General

✓ STRM

NIST

NIST SP 800-66 R2 - Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-66-r2.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - High Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2-high.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Moderate Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2-mod.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Low Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2-low.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations - Privacy Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2-privacy.pdf)

General

✓ STRM

NIST

NIST SP 800-53 R5 - Security and Privacy Controls for Information Systems and Organizations

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-53-r5-2.pdf)

General

✓ STRM

NIST

NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-39.pdf)

General

✓ STRM

NIST

NIST SP 800-37 R2 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-800-37-r2.pdf)

General

✓ STRM

NIST

NIST Privacy Framework v1.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-privacy-framework-1-0.pdf)

General

✓ STRM

NIST

NIST AI 600-1 - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-600-1-gen-ai-profile.pdf)

General

✓ STRM

NIST

NIST AI 100-1 - Artificial Intelligence Risk Management Framework (AI RMF 1.0)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-nist-100-1-ai-rmf.pdf)

General

✓ STRM

NAIC

National Association of Insurance Commissioners Insurance Data Security Model Law (MDL-668) (2017)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-naic-insurance-data-security-model-law-668-2017.pdf)

General

✓ STRM

MPA

Motion Picture Association (MPA) Content Security Best Practices Common Guidelines v5.3.1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-mpa-csbp-5-3-1.pdf)

General

✓ STRM

MITRE

MITRE Adversarial Tactics, Techniques, and Common Knowledge - NIST 800-53 mappings

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-mitre-att&ck-16-1.pdf)

General

✓ STRM

ISO

ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-42001-2023.pdf)

General

✓ STRM

ISO

IEC 31010:2019 - Risk management - Risk assessment techniques

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-31010-2009.pdf)

General

✓ STRM

ISO

ISO/IEC 29100:2024 - Information technology - Security techniques - Privacy framework

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-29100-2024.pdf)

General

✓ STRM

ISO

ISO 31000:2018 - Risk management - Guidelines

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-31000-2018.pdf)

General

✓ STRM

ISO

ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems - Requirements and guidance

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27701-2025.pdf)

General

✓ STRM

ISO

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27018-2025.pdf)

General

✓ STRM

ISO

ISO/IEC 27017:2015 - Information technology - Security techniques -Code of practice for information security controls based on ISO/IEC 27002 for cloud services

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27017-2015.pdf)

General

✓ STRM

ISO

ISO/IEC 27002:2022 - Information security, cybersecurity and privacy protection - Information security controls

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27002-2022.pdf)

General

✓ STRM

ISO

ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-27001-2022.pdf)

General

✓ STRM

ISO

ISO 22301:2019 - Security and resilience - Business continuity management systems - Requirements

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-22301-2019.pdf)

General

✓ STRM

IEC

ISO/SAE 21434:2021 - Road vehicles - Cybersecurity engineering

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iso-21434-2021.pdf)

General

✓ STRM

IMO

International Maritime Organization (IMO) Guidelines on Maritime Cyber Risk Management (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-imo-maritime-cyber-risk-management-2025.pdf)

General

✓ STRM

IEC

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-62443-4-1-2018.pdf)

General

✓ STRM

IEC

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-62443-4-2-2019.pdf)

General

✓ STRM

IEC

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-62443-3-3-2013.pdf)

General

✓ STRM

IEC

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-62443-2-1-2024.pdf)

General

✓ STRM

IEC

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-iec-tr-60601-4-5-2021.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - High

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-high.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Moderate

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-mod.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Core Controls

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-core.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Low+

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-low-plus.pdf)

General

✓ STRM

GovRAMP

Government Risk and Authorization Management Program (GovRAMP) - Low

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-govramp-low.pdf)

General

✓ STRM

CR

Cyber Resilience Capability Maturity Model (CR-CMM) (2026)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cr-cmm-2026.pdf)

General

✓ STRM

COSO

Committee of Sponsoring Organizations (COSO) (2013)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-coso-2013.pdf)

General

✓ STRM

CSA

Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.1.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-csa-cmm-4-1-0.pdf)

General

✓ STRM

ISACA

Control Objectives for Information and Related Technologies (COBIT) (2019)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cobit-2019.pdf)

General

✓ STRM

CSA

Cloud Security Alliance (CSA) Internet of Things Security Controls Framework v2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-csa-iot-2.pdf)

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG3

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cis-csc-8-1-ig3.pdf)

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cis-csc-8-1-ig2.pdf)

General

✓ STRM

APEC

Asia-Pacific Economic Cooperation (APEC) Privacy Framework (2015)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-apec-privacy-framework-2015.pdf)

General

✓ STRM

BSI

Bundesamt für Sicherheit in der Informationstechnik (BSI) - Standard 200-1 (v1.0)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-bsi-200-1-1-0.pdf)

General

✓ STRM

AICPA

American Institute of Certified Public Accountants (AICPA) Trust Services Criteria (2017)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-aicpa-tsc-2017.pdf)

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cis-csc-8-1.pdf)

General

✓ STRM

AICPA

American Institute of Certified Public Accountants (AICPA) Privacy Management Framework (PMF) (2020)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-aicpa-pmf-2020.pdf)

General

✓ STRM

CIS

Center for Internet Security (CIS) Critical Security Controls (CSC) version 8.1 - IG1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-general-cis-csc-8-1-ig1.pdf)

[Previous](/content/start-here/set-theory-relationship-mapping-strm?32c49cd9_page=4/index.html) [Next](/content/start-here/set-theory-relationship-mapping-strm?32c49cd9_page=2/index.html)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

USA

✓ STRM

State

Colorado Privacy Act (2021)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-co-privacy-act-2021.pdf)

USA

✓ STRM

State

Virginia Consumer Data Protection Act (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-va-cdpa-2023.pdf)

USA

✓ STRM

State

Vermont Data Broker Registration Act (Act 171 of 2018)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-vt-act-171-2018.pdf)

USA

✓ STRM

State

Texas Risk & Authorization Management Program 2.0 - Level 2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-txramp-2-0-level-2.pdf)

USA

✓ STRM

State

Texas Safe Harbor Law (SB2610) (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-sb2610-2025.pdf)

USA

✓ STRM

State

Texas Risk & Authorization Management Program 2.0 - Level 1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-txramp-2-0-level-1.pdf)

USA

✓ STRM

State

Texas SB820 (2019)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-sb820-2019.pdf)

USA

✓ STRM

State

Tennessee Information Protection Act (TIPA) (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tn-tipa-2025.pdf)

USA

✓ STRM

State

Texas Identity Theft Enforcement and Protection Act (BC521) (2009)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-bc521-2009.pdf)

USA

✓ STRM

State

Texas DIR Security Control Standards Catalog v2.2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-dir-security-control-standards-catalog-2-2.pdf)

USA

✓ STRM

State

Texas Consumer Data Protection Act (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-tx-cdpa-2025.pdf)

USA

✓ STRM

State

New York Department of Financial Services 23NYCRR Part 500 (2023 Amendment 2)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ny-dfs-23-nycrr500-2023-amd2.pdf)

USA

✓ STRM

State

Oregon Consumer Privacy Act (SB 619) (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-or-cpa-2023.pdf)

USA

✓ STRM

State

Oregon Consumer Information Protection Act (ORS 646A) (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-or-ors-646a-2025.pdf)

USA

✓ STRM

State

New York SHIELD Act (SB S5575B) (2019)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ny-shield-act-2019.pdf)

USA

✓ STRM

State

Nevada SB220 (2019)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-nv-sb220-2019.pdf)

USA

✓ STRM

State

Nevada Privacy Law (2023)- CHAPTER 603A - SECURITY AND PRIVACY OF PERSONAL INFORMATION

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-nv-privacy-law-2023.pdf)

USA

✓ STRM

State

Nevada Operation of Gaming Establishments - Regulation 5.260 (Cybersecurity)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-nv-regulation-5-2024.pdf)

USA

✓ STRM

State

Massachusetts 201 CMR 17.00 (2008)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ma-201-cmr-17-2008.pdf)

USA

✓ STRM

State

Illinois Personal Information Protection Act (PIPA) (2006)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-il-pipa-2006.pdf)

USA

✓ STRM

State

Illinois Identity Protection Act (IPA) (2009)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-il-ipa-2009.pdf)

USA

✓ STRM

State

Illinois Biometric Information Privacy Act (BIPA) (2008)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-il-bipa-2008.pdf)

USA

✓ STRM

State

California SB1386 (2002)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ca-sb1386-2002.pdf)

USA

✓ STRM

State

California SB327 (2018)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ca-sb327-2018.pdf)

USA

✓ STRM

State

Alaska Personal Information Protection Act (PIPA) (2009)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ak-pipa-2009.pdf)

USA

✓ STRM

State

California Consumer Privacy Act (CCPA) (January 2026) - amended California Privacy Rights Act (CPRA)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-state-ca-ccpa-cpra-2026.pdf)

USA

✓ STRM

Federal

Transportation Security Administration Security Directive 1580/82-2022-01 - Rail Cybersecurity Mitigation Actions and Testing

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-tsa-security-directive-1580-82-2022-01.pdf)

USA

✓ STRM

Federal

Sarbanes Oxley Act (2002)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-sox-2002.pdf)

USA

✓ STRM

Federal

SEC Cybersecurity Rule (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-sec-cybersecurity-rule-2023.pdf)

USA

✓ STRM

Federal

North American Electric Reliability Corporation Critical Infrastructure Protection (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-nerc-cip-2024.pdf)

USA

✓ STRM

Federal

National Industrial Security Program Operating Manual (2020)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-nispom-2020.pdf)

USA

✓ STRM

Federal

Safeguarding of Naval Nuclear Propulsion Information (NNPI) (2010)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-safeguarding-nnpi-2010.pdf)

USA

✓ STRM

Federal

US Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-cms-marse-2-0.pdf)

USA

✓ STRM

Federal

Internal Revenue Service 1075 (2021)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-irs-1075-2021.pdf)

USA

✓ STRM

Federal

HIPAA Security Rule (2013)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-hipaa-security-rule-2013.pdf)

USA

✓ STRM

Federal

HIPAA Administrative Simplification (2013)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-hipaa-simplification-2013.pdf)

USA

✓ STRM

Federal

Gramm Leach Bliley Act - CFR 314 (Dec 2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-glba-cfr-314-2023.pdf)

USA

✓ STRM

Federal

HHS § 155.260 - Privacy and Security of Personally Identifiable Information (2016)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-hhs-45-cfr-155-260-2016.pdf)

USA

✓ STRM

Federal

Federal Trade Commission (FTC) Act

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-ftc-act.pdf)

USA

✓ STRM

Federal

US Fair Information Practice Principles (FIPPs) (1973)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-omb-fipps-1973.pdf)

USA

✓ STRM

Federal

Financial Industry Regulatory Authority (FINRA) Cybersecurity Rules

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-sro-finra.pdf)

USA

✓ STRM

Federal

Family Educational Rights and Privacy Act (FERPA) (2010)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-ferpa-2010.pdf)

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Li-SAAS Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-gsa-fedramp-5-li-saas.pdf)

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - High Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-gsa-fedramp-5-high.pdf)

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Moderate Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-gsa-fedramp-5-mod.pdf)

USA

✓ STRM

Federal

Federal Risk and Authorization Management Program R5 - Low Baseline

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-gsa-fedramp-5-low.pdf)

USA

✓ STRM

Federal

Food & Drug Administration 21 CFR Part 11 (2025)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-fda-21-cfr-part-11-2025.pdf)

USA

✓ STRM

Federal

Farm Credit Administration Cyber Risk Management (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-sro-fca-crm-2023.pdf)

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-27 - Prohibition on a ByteDance Covered Application

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-far-52-204-27.pdf)

USA

✓ STRM

Federal

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-far-52-204-25.pdf)

USA

✓ STRM

Federal

Federal Acquisition Regulation 52.204-21 - Basic Safeguarding of Covered Contractor Information Systems

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-far-52-204-21.pdf)

USA

✓ STRM

Federal

Fair & Accurate Credit Transactions Act (FACTA) & Fair Credit Reporting Act (FCRA) (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-facta-fcra-2023.pdf)

USA

✓ STRM

Federal

Executive Order 14028 - Improving the Nation's Cybersecurity

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-eo-14028.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Zero Trust Reference Architecture v2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-zta-reference-architecture-2-0.pdf)

USA

✓ STRM

Federal

Defense Federal Acquisition Regulation Supplement 252.204-7012

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-dfars-252-204-7012.pdf)

USA

✓ STRM

Federal

Data Privacy Framework (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-doc-data-privacy-framework-2023.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Zero Trust Execution Roadmap v1.1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-zt-roadmap-1-1.pdf)

USA

✓ STRM

Federal

US Department of Justice - Criminal Justice Information Services (CJIS) Security Policy v6.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-fbi-cjis-6-0.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 3

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cmmc-2-level-3.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cmmc-2-level-2.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 1 Assessment Objectives

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cmmc-2-level-1-aos.pdf)

USA

✓ STRM

Federal

Department of War (DoW) - Cybersecurity Maturity Model Certification v2.0 - Level 1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cmmc-2-level-1.pdf)

USA

✓ STRM

Federal

Department of Energy (DOE) - Cybersecurity Capability Maturity Model version 2.1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-doe-c2m2-2-1.pdf)

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals 2.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dhs-cisa-cpg-2-0.pdf)

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Trusted Internet Connections 3.0 Security Capabilities Catalog

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dhs-cisa-tic-3-0.pdf)

USA

✓ STRM

Federal

Cybersecurity & Infrastructure Security Agency (CISA) Secure Software Development Attestation Form (SSDAF) (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dhs-cisa-ssdaf-2024.pdf)

USA

✓ STRM

Federal

Children's Online Privacy Protection Act (COPPA) (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-law-coppa-2024.pdf)

USA

✓ STRM

Federal

US Computer Emergency Response Team Resilience Management Model Version 1.2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-usa-federal-dow-cert-rmm-1-2.pdf)

[Previous](/content/start-here/set-theory-relationship-mapping-strm?0316a396_page=3/index.html) [Next](/content/start-here/set-theory-relationship-mapping-strm?0316a396_page=2/index.html)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L3

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-l3-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L2

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-l2-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-l0-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024) - L1

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-l1-2024.pdf)

EMEA

✓ STRM

United Kingdom

UK - Ministry of Defence Standard 05-138 (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-def-stan-05-138-2024.pdf)

EMEA

✓ STRM

Spain

Royal Decree 311/2022, of May 3, which regulates the National Security Scheme (BOE-A-2022-7191)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-esp-boe-a-2022-7191.pdf)

EMEA

✓ STRM

United Kingdom

UK - Cyber Assessment Framework (CAF) v4.0

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-gbr-caf-4-0.pdf)

EMEA

✓ STRM

UAE

UAE - National Information Assurance Framework (NIAF) (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-uae-niaf-2023.pdf)

EMEA

✓ STRM

Saudi Arabia

Saudi Arabia - Personal Data Protection Law (PDPL) (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-sau-pdpl-2023.pdf)

EMEA

✓ STRM

Saudi Arabia

Saudi Arabia - Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-sau-cgiot-2024.pdf)

EMEA

✓ STRM

EU

European Union Agency for Cybersecurity NIS2 (Directive (EU) 2022/2555)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-nis2-2022.pdf)

EMEA

✓ STRM

EU

European Union Agency for Cybersecurity NIS2 Annex (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-nis2-annex-2024.pdf)

EMEA

✓ STRM

EU

European Union General Data Protection Regulation (2016)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-gdpr-2016.pdf)

EMEA

✓ STRM

EU

Digital Operational Resilience Act (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-dora-2023.pdf)

EMEA

✓ STRM

EU

European Union Cyber Resilience Act - Annexes (2022)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-cyber-resilience-act-annexes-2022.pdf)

EMEA

✓ STRM

EU

European Union Cyber Resilience Act (2022)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-cyber-resilience-act-2022.pdf)

EMEA

✓ STRM

EU

European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-emea-eu-ai-act-2024.pdf)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

APAC

✓ STRM

New Zealand

New Zealand - HISO 10029:2024 NZ Health Information Security Framework Guidance for Suppliers

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-nzl-hisf-suppliers-2023.pdf)

APAC

✓ STRM

New Zealand

New Zealand - HISF MicroSmall (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-nzl-hisf-microsmall-2023.pdf)

APAC

✓ STRM

New Zealand

New Zealand - HISF MLHSP (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-nzl-hisf-mlhsp-2023.pdf)

APAC

✓ STRM

India

India - SEBI Cybersecurity and Cyber Resilience Framework (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-ind-sebi-2024.pdf)

APAC

✓ STRM

India

India Digital Personal Data Protection Act (2023)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-ind-dpdpa-2023.pdf)

APAC

✓ STRM

China

China - Cybersecurity Law of the People's Republic of China (2017)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-chn-cybersecurity-law-2017.pdf)

APAC

✓ STRM

Australia

Australia - Information Security Manual (ISM) (June 2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-aus-ism-2024-june.pdf)

APAC

✓ STRM

Australia

Australia -Essential Eight maturity model and ISM mapping (2024)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-apac-aus-essential-8-2024.pdf)

No matching frameworks found. Try a different search term or filter.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

Americas

✓ STRM

Canada

Canada - Protecting controlled information in non-Government of Canada systems and organizations (ITSP.10.171)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-americas-can-itsp-10-171-2025.pdf)

Americas

✓ STRM

Canada

Canada - OSFI B-13 (2022)

[Download STRM (PDF) →](https://content.securecontrolsframework.com/strm/scf-strm-americas-can-osfi-b13-2022.pdf)

No matching frameworks found. Try a different search term or filter.

Community Involvement

## How To Submit a Community STRM Mapping

The SCF welcomes community involvement. The SCF Council provides a downloadable [Community STRM Template](https://content.securecontrolsframework.com/strm/scf-community-strm-template.xlsx) that practitioners can use to perform their own crosswalk mapping and submit for possible inclusion in a future SCF release.

01

### Define the Focal Document

Open the STRM template’s “STRM Overview” tab and complete the two highlighted cells identifying:

- The Focal Document (FD), which is the law, regulation or framework you are mapping
- The Reference Document (RD), which is the SCF (the document being mapped to)

Prerequisites: familiarity with NIST IR 8477 and professional competence to conduct crosswalk mapping.

02

### Perform the STRM Mapping

Complete the “Community STRM submission” tab using these columns:

- FDE number (mandatory unique identifier)
- FDE name (if available)
- FDE description (exact text of the requirement)
- Proposed SCF control name
- SCF control number
- SCF control description
- STRM relationship type (1 of 5 options)
- Relationship strength (1–10 rating)
- Optional notes / justification

03

### Submit to the SCF Council

Once your STRM exercise is complete, email the completed Excel spreadsheet to the SCF Council for review:

[support@securecontrolsframework.com](mailto:support@securecontrolsframework.com?subject=Contact%20The%20SCF%20Council)

Submissions are evaluated by the SCF Council and may be included in a future SCF release. The SCF Council will contact you if there are questions about your submission.

Additional SCF Content

## Explore Further

#### Included LRF

Browse all 200+ laws, regulations and frameworks mapped in the SCF across 5 global regions.

[Learn more **→**](/content/start-here/included-laws-regulations-frameworks-lrf/index.html)

#### NIST OLIR Participation

The SCF is a recognized NIST OLIR Program participant with accepted OLIRs for NIST CSF v1.1 and SP 800-171 R2.

[Learn more **→**](/content/start-here/nist-olir-participation/index.html)

#### SCF Domains

Explore the 33 control domains that form the Common Controls Framework at the heart of the SCF.

[Learn more **→**](/content/start-here/scf-domains-principles/index.html)

#### Download the SCF

Get the free SCF spreadsheet with all controls, all LRF mappings, and all STRM relationships included.

[Download The SCF](/content/free-content/scf-download/index.html)

### Join 25,000+ GRC Professionals

Get the latest SCF updates, cybersecurity insights, and community news delivered to your inbox. You know you want to do it!

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

%20(white).png)

Controls are your security, compliance & resilience program - A control is the power to influence or direct behaviors and the course of events.

‍

[DOWNLOAD THE SCF](/content/free-content/scf-download/index.html)

Start Here

[What Is The SCF?](/content/start-here/index.html) [How To Implement (SCRMS)](/content/start-here/security-compliance-resilience-management-system-scrms/index.html) [Domains & Principles](/content/start-here/scf-domains-principles/index.html) [Laws & Frameworks (LRF)](/content/start-here/included-laws-regulations-frameworks-lrf/index.html) [Relationship Mapping (STRM)](/content/start-here/set-theory-relationship-mapping-strm/index.html) [NIST OLIR Participation](/content/start-here/nist-olir-participation/index.html) [ESG Considerations](/content/start-here/esg-considerations/index.html)

Free Content

[SCF Download](/content/free-content/scf-download/index.html) [Risk Management (SCR-RMM)](/content/free-content/risk-management-model-scr-rmm/index.html) [Maturity Model (SCR-CMM)](/content/free-content/capability-maturity-model-scr-cmm/index.html) [Assessment Standards (CDPAS)](/content/free-content/cybersecurity-assessment-standards-cdpas/index.html) [Mergers & Acquisitions (MA&D)](/content/free-content/mergers-acquisitions-divestitures-ma-d/index.html) [Privacy Principles (DPMP)](/content/free-content/data-privacy-management-principles-dpmp/index.html) [Evidence Request List (ERL)](/content/free-content/evidence-request-list-erl/index.html) [Scoping Guide (USG)](/content/free-content/unified-scoping-guide-usg/index.html)

Resources

[GRC Fundamentals](/content/grc-fundamentals/index.html) [SCF Certified](/content/scf-certified/index.html) [Marketplace](/content/marketplace/index.html) [FAQ](/content/faq/index.html) [About](/content/about/index.html) [Blog](/content/blog/index.html)

Support

[Donate](https://buy.stripe.com/eVa8yJ4aIf9c75e288) [Volunteer](/content/contact-us/index.html)

© 2026 Secure Controls Framework Council, LLC. All rights reserved.

[Terms & Conditions](/content/terms-and-conditions/index.html) [Privacy](/content/privacy-notice/index.html) [Cookies](/content/privacy-notice/index.html) [Sitemap](/content/sitemap.xml)
