# securecontrolsframework.com > AI-optimized mirror of securecontrolsframework.com containing 50 pages totalling 62,471 words of clean markdown content, structured data, and semantic HTML. Original source: https://securecontrolsframework.com/. Last updated: 2026-06-10T15:55:54.097Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [The Secure Controls Framework® (SCF)](/content/site-root.html): The SCF is the world's #1 free cybersecurity and data privacy metaframework. 1,400+ controls mapped to 200+ laws, regulations, frameworks. (1,496 words) ## Articles & Blog Posts - [grc-fundamentals/common-cybersecurity-laws/us-fed-hipaa-hitech/index.html](/content/grc-fundamentals/common-cybersecurity-laws/us-fed-hipaa-hitech/index.html) (1 words) - [grc-fundamentals/common-cybersecurity-frameworks/trust-services-criteria-soc-2/index.html](/content/grc-fundamentals/common-cybersecurity-frameworks/trust-services-criteria-soc-2/index.html) (1 words) - [free-content/cybersecurity-assessment-standards-cdpas/index.html](/content/free-content/cybersecurity-assessment-standards-cdpas/index.html) (1 words) - [grc-fundamentals/emerging-trends/index.html](/content/grc-fundamentals/emerging-trends/index.html) (1 words) - [Common Cybersecurity Frameworks](/content/grc-fundamentals/common-cybersecurity-frameworks/index.html): Overview of the most-used cybersecurity frameworks: NIST CSF, NIST 800-53, NIST 800-171, ISO 27001, SOC 2, PCI DSS, HITRUST, and CIS Controls. (763 words) - [grc-fundamentals/common-cybersecurity-laws/eu-gdpr/index.html](/content/grc-fundamentals/common-cybersecurity-laws/eu-gdpr/index.html) (1 words) - [grc-fundamentals/common-cybersecurity-laws/index.html](/content/grc-fundamentals/common-cybersecurity-laws/index.html) (1 words) - [Common Cybersecurity Frameworks](/content/grc-fundamentals/common-cybersecurity-frameworks/nist-csf-2-0/index.html): NIST CSF 2.0 explained: the six core functions (Govern, Identify, Protect, Detect, Respond, Recover), who should use it, and how it ties to SCF. (1,370 words) - [SCF Domains & Principles](/content/start-here/scf-domains-principles/index.html): Explore the 33 cybersecurity and data privacy domains in the SCF, from Governance and Risk Management to Cryptography and Incident Response. (1,140 words) - [grc-fundamentals/common-cybersecurity-regulations/us-fed-cmmc/index.html](/content/grc-fundamentals/common-cybersecurity-regulations/us-fed-cmmc/index.html) (1 words) - [grc-fundamentals/word-crimes/index.html](/content/grc-fundamentals/word-crimes/index.html) (1 words) - [Free Cybersecurity & GRC Content](/content/free-content/index.html): Free GRC tools from the SCF: control downloads, maturity models, risk frameworks, scoping guides, evidence request lists, and more. No cost. (1,494 words) - [grc-fundamentals/common-cybersecurity-frameworks/metaframwork-hitrust/index.html](/content/grc-fundamentals/common-cybersecurity-frameworks/metaframwork-hitrust/index.html) (1 words) - [grc-fundamentals/index.html](/content/grc-fundamentals/index.html) (1 words) - [Texas Senate Bill 2610: Cybersecurity Safe Harbor](/content/grc-fundamentals/common-cybersecurity-laws/us-tx-sb-2610/index.html): Texas Senate Bill 2610 is a safe harbor law that protects businesses from liability if they adopt a recognized framework like the SCF. (1,162 words) - [NIST OLIR Project SCF Participation](/content/start-here/nist-olir-participation/index.html): The SCF participates in NIST's Online Informative References (OLIR) program, contributing authoritative crosswalk mappings to NIST frameworks. (668 words) - [Laws vs Regulations vs Frameworks](/content/grc-fundamentals/grc-basics/laws-vs-regulations-vs-frameworks/index.html): What's the difference between a cybersecurity law, regulation, and framework? A clear, practitioner-level explanation with examples of each. (973 words) - [MADSS: Mergers, Acquisitions & Divestitures Security Standards](/content/free-content/mergers-acquisitions-divestitures-ma-d/index.html): The MADSS is the SCF's free standard for cybersecurity due diligence during mergers, acquisitions, and divestitures. Reduce deal risk. (1,662 words) - [Evidence Request List (ERL)](/content/free-content/evidence-request-list-erl/index.html): The SCF Evidence Request List (ERL) is a free audit checklist mapping expected artifacts to each SCF control — defensible, reusable, ready. (1,658 words) - [GRC Fundamentals](/content/grc-fundamentals/common-cybersecurity-regulations/index.html): Summaries of the cybersecurity regulations every GRC practitioner should know: CMMC, DFARS 252.204-70XX, NY DFS 23 NYCRR 500, and other US rules. (616 words) - [Payment Card Industry Data Security Standard](/content/grc-fundamentals/common-cybersecurity-frameworks/pci-dss/index.html): PCI DSS explained: the 12 requirements, SAQ levels, Report on Compliance (ROC), PCI DSS 4.0 changes, and who must comply. (1,403 words) - [Unified Scoping Guide (USG)](/content/free-content/unified-scoping-guide-usg/index.html): The USG is the SCF's free guide for scoping cybersecurity assessments. Reduce audit ambiguity with a clear, repeatable scoping method. (1,645 words) - [grc-fundamentals/common-cybersecurity-frameworks/nist-sp-800-161/index.html](/content/grc-fundamentals/common-cybersecurity-frameworks/nist-sp-800-161/index.html) (1 words) - [SCR-RMM: Risk Management Model](/content/free-content/risk-management-model-scr-rmm/index.html): The SCR-RMM is the SCF's controls-centric risk management model. Free catalog of cybersecurity risks and threats mapped to SCF controls. (4,372 words) - [Cybersecurity ESG Considerations](/content/start-here/esg-considerations/index.html): How the SCF supports Environmental, Social & Governance (ESG) reporting with cybersecurity controls that map to disclosure and materiality rules. (1,171 words) - [DPMP: Data Privacy Management Principles](/content/free-content/data-privacy-management-principles-dpmp/index.html): The DPMP is the SCF's free framework for building a privacy program. Principles-based guidance for GDPR, CCPA, HIPAA, and global privacy rules. (1,364 words) - [Sarbanes-Oxley Act of 2002 (SOX)](/content/grc-fundamentals/common-cybersecurity-laws/us-fed-sox/index.html): The Sarbanes-Oxley Act explained: Section 302 and 404 requirements, IT general controls (ITGCs), audit expectations, and cybersecurity overlap. (1,382 words) - [Included Laws, Regulations & Frameworks (LRF)](/content/start-here/included-laws-regulations-frameworks-lrf/index.html): Searchable list of every law, regulation, and framework the SCF maps to — NIST, ISO, GDPR, HIPAA, PCI DSS, CMMC, and 200+ more. Browse now! (8,514 words) - [sitemap-xml.html](/content/sitemap-xml.html) (82 words) - [GRC Fundamentals](/content/grc-fundamentals/common-cybersecurity-frameworks/nist-sp-800-171/index.html): NIST SP 800-171 Rev 3 explained: how defense contractors protect CUI, what changed from Rev 2, its role in CMMC, and SCF compliance. (1,239 words) - [Digital Operational Resilience Act (DORA)](/content/grc-fundamentals/common-cybersecurity-laws/eu-dora/index.html): The EU's Digital Operational Resilience Act (DORA) explained: who it applies to, ICT risk requirements, incident reporting, and deadlines. (1,220 words) - [Unified Compliance (UC / UCF)](/content/grc-fundamentals/common-cybersecurity-frameworks/metaframework-unified-compliance-uc/index.html): The Unified Compliance Framework (UCF) is a commercial metaframework. What it covers, how it's licensed, and how it compares to the SCF. (1,234 words) - [grc-fundamentals/common-cybersecurity-regulations/us-fed-dfars-252-204-70xx/index.html](/content/grc-fundamentals/common-cybersecurity-regulations/us-fed-dfars-252-204-70xx/index.html) (1 words) - [GRC Fundamentals](/content/grc-fundamentals/grc-basics/the-output-of-grc-practices/index.html): How to determine cybersecurity materiality under SEC disclosure rules. Practical guidance for public companies on what must be disclosed. (1,253 words) - [grc-fundamentals/common-cybersecurity-laws/us-fed-fedramp/index.html](/content/grc-fundamentals/common-cybersecurity-laws/us-fed-fedramp/index.html) (1 words) - [GRC Fundamentals](/content/grc-fundamentals/common-cybersecurity-frameworks/cis-critical-security-controls-csc/index.html): The CIS Critical Security Controls are 18 prioritized, community-developed safeguards for defending against the most common cyber attacks. (853 words) - [Common Cybersecurity Frameworks](/content/grc-fundamentals/common-cybersecurity-frameworks/iso-27001-iso-27002/index.html): ISO 27001 and ISO 27002 explained: the international ISMS standard, Annex A controls, certification process, and how it compares to NIST. (1,400 words) - [SCF Download: The Common Controls Framework™ Free For Everyone](/content/free-content/scf-download/index.html): Download the SCF free in Excel or NIST OSCAL JSON. 1,400+ controls, 200+ framework mappings, maturity criteria, and risk/threat catalogs inside. (981 words) - [Security, Compliance & Resilience Management System (SCRMS)](/content/start-here/security-compliance-resilience-management-system-scrms.html): The Security, Compliance & Resilience Management System (SCRMS) is the SCF's implementation playbook — a controls-centric approach to GRC. (2,158 words) - [California Consumer Privacy Act / California Privacy Rights Act](/content/grc-fundamentals/common-cybersecurity-laws/us-ca-ccpa-cpra/index.html): California's CCPA and CPRA explained: consumer rights, business obligations, applicability thresholds, and how to operationalize compliance. (1,321 words) - [faq/index.html](/content/faq/index.html) (1 words) - [GRC Fundamentals](/content/grc-fundamentals/common-cybersecurity-frameworks/nist-sp-800-53/index.html): NIST SP 800-53 Rev 5 explained: the 20 control families, baselines, who must comply, and how the SCF maps to every 800-53 control. (1,192 words) - [Cybersecurity Materiality](/content/grc-fundamentals/grc-basics/cybersecurity-materiality/index.html): How to determine cybersecurity materiality under SEC disclosure rules. Practical guidance for public companies on what must be disclosed. (1,330 words) - [Gramm-Leach-Bliley Act (GLBA)](/content/grc-fundamentals/common-cybersecurity-laws/us-fed-glba/index.html): The Gramm-Leach-Bliley Act explained: the Safeguards Rule, Privacy Rule, who it applies to in financial services, and recent FTC amendments. (1,620 words) - [Set Theory Relationship Mapping (STRM)](/content/start-here/set-theory-relationship-mapping-strm/index.html): STRM is the NIST IR 8477 methodology the SCF uses for every crosswalk. Rigorous set-theory mapping makes SCF coverage defensible and auditable. (6,397 words) - [Network and Information Security 2 (NIS2) Directive](/content/grc-fundamentals/common-cybersecurity-laws/eu-nis2-directive/index.html): The EU NIS2 Directive explained: which essential and important entities must comply, the security measures required, and how NIS2 expands NIS. (1,008 words) - [NIST SP 800-172](/content/grc-fundamentals/common-cybersecurity-frameworks/nist-sp-800-172/index.html): ISO 27001 and ISO 27002 explained: the international ISMS standard, Annex A controls, certification process, and how it compares to NIST (1,174 words) - [SCR-CMM: Capability Maturity Model. Measure & Advance Your Cybersecurity Program](/content/free-content/capability-maturity-model-scr-cmm/index.html): The SCR-CMM is the SCF's free 5-level capability maturity model for cybersecurity controls — from Ad Hoc to Optimized. Score your program. (3,244 words) - [NY DFS 23 NYCRR Part 500](/content/grc-fundamentals/common-cybersecurity-regulations/us-ny-ny-dfs-23-nycrr-part-500/index.html): New York DFS 23 NYCRR Part 500 explained: covered entities, cybersecurity program requirements, the 2023 amendments, and how to comply. (1,898 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives