Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Free Education Resources - Cybersecurity & Privacy

At ComplianceForge, we pride ourselves on the level of educational material we provide to clients, so that they have a firm understanding of their requirements. We provide these resources at no-cost, so you are free to download them. If you have any questions, please contact us.

NIST Cybersecurity Framework vs ISO 27002 vs NIST 800-55 vs Secure Controls Framework (SCF)

Helpful information pertaining to selecting the appropriate cybersecurity framework for your needs, specifically NIST Cybersecurity Framework, ISO 27002, NIST 800-53 and the Secure Controls Framework (SCF).

Understanding Cybersecurity & Privacy Requirements: Statutory vs Regulatory vs Contractual Obligations

Free guide to understanding the difference between cybersecurity & privacy compliance requirements, specifically statutory, regulatory and contractual obligations.

Understanding Cybersecurity & Privacy Documentation: Policies vs Standards vs Procedures

Free guide to understanding the terminology of cybersecurity and privacy documentation, specifically, policies, standards, controls and procedures.

Free NIST 800-171 / Cybersecurity Maturity Model Certification (CMMC) Compliance Scoping Guide

We put together several videos and a scoping guide to help businesses understand their needs for complying with NIST 800-171. Those free resources can be found here.

EU GDPR Compliance Criteria (EGCC)

The European Union General Data Protection Regulation (EU GDPR) is a hot topic and we worked with the Secure Controls Framework (SCF) to develop the EU GDPR Compliance Criteria (EGCC), which is a free tool for businesses to understand their compliance needs and map those requirements to their existing cybersecurity and privacy principles. You can access the EGCC here.

Free Guide To Cybersecurity Policies & Standards

We wrote a primer on cybersecurity documentation to help explain the components that go into making hierarchical, scalable cybersecurity documentation. That can be found here.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about our free cybersecurity guides:

Are ComplianceForge's cybersecurity guides really free?
Yes, ComplianceForge's cybersecurity and privacy guides are free, and you're welcome to download them. We publish this educational material to give you a firm understanding of your requirements. Topics include compliance obligations, documentation terminology, framework selection and NIST 800-171 and CMMC scoping. If you have questions about a guide, you can contact us directly by phone or through our contact page.
What free cybersecurity guides does ComplianceForge offer?
ComplianceForge offers free guides on cybersecurity frameworks, compliance obligations, documentation terminology, scoping and privacy. They include a comparison of NIST CSF, ISO 27002, NIST 800-53 and the Secure Controls Framework (SCF), a guide to statutory, regulatory and contractual obligations, and a primer on policies, standards and procedures. We also publish NIST 800-171 and CMMC scoping resources, the EU GDPR Compliance Criteria (EGCC), and separate guides on CONOPS, metrics reporting, supply chain risk and the CIAS model.
Is there a free NIST 800-171 and CMMC scoping guide?
Yes, ComplianceForge publishes free NIST 800-171 and CMMC scoping resources, including videos and the Unified Scoping Guide (USG). The USG is a free resource that categorizes systems by whether they store, process or transmit sensitive data such as Controlled Unclassified Information (CUI), what function they perform, and how they connect to the sensitive data environment. Good scoping matters because it determines which systems are in scope for an assessment.
What is the EU GDPR Compliance Criteria (EGCC)?
The EU GDPR Compliance Criteria (EGCC) is a free resource that ComplianceForge created with the Secure Controls Framework (SCF) to help you understand and manage your GDPR-related controls. It maps GDPR articles to SCF controls, to cybersecurity frameworks such as NIST 800-53, ISO 27002 and the NIST Cybersecurity Framework, and to privacy frameworks such as SOC 2 and GAPP. It also includes a RACI-style view of the parties most commonly involved in managing each control.
Why does cybersecurity documentation terminology matter for compliance?
Documentation terminology matters because misusing terms such as policy and standard has cascading effects that can weaken an organization's internal controls. Cybersecurity, technology, privacy and legal professionals routinely use these words as if they were synonyms, but they aren't. ComplianceForge's free Policies vs Standards vs Procedures guide gives plain-language definitions of policies, control objectives, standards, guidelines, procedures and metrics so your teams can apply each term consistently.