Cybersecurity Compliance Starts With Unambiguous Documentation
ComplianceForge documentation is designed to scale for any cybersecurity or data privacy compliance need. Our clients have successfully used ComplianceForge documentation for a wide variety of compliance efforts, including:
NIST 800-171 / Cybersecurity Maturity Model Certification (CMMC)
Payment Card Industry Data Security Standard (PCI DSS)
ISO 27001
System and Organization Controls (SOC 2)
Health Insurance Portability and Accountability Act (HIPAA) / Health Information Technology for Economic and Clinical Health Act (HITECH)
Federal Risk and Authorization Management Program (FedRAMP)
Federal Information Security Modernization Act (FISMA)
Risk Management Framework (RMF) / DoD Information Assurance Certification and Accreditation Process (DIACAP)
Criminal Justice Information Services (CJIS)
Family Educational Rights and Privacy Act (FERPA)
Internal Revenue Service (IRS) 1075
European Union General Data Protection Regulation (EU GDPR)
Gramm-Leach-Bliley Act (GLBA)
Sarbanes–Oxley Act (SOX)
Federal Financial Institutions Examination Council (FFIEC)
California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
New York Department of Financial Services (23 NYCRR 500)
And more!
There are a lot of cybersecurity and data privacy compliance requirements, but only a fraction have the ability to earn a certification. To address the needs of businesses that want to demonstrate compliance via a third-party assessment, the Secure Controls Framework (SCF) developed a conformity assessment methodology. The Cyber AB (same accreditation body as the DoD uses for CMMC) is the SCF's accrediation body for the SCF's Conformity Assessment Program (SCF CAP).
Secure Controls Framework Conformity Assessment Program (SCF CAP)
The Secure Controls Framework Conformity Assessment Program (SCF CAP) is a new approach to cybersecurity certifcations, since it enables an organization to demonstrate compliance with a law, regulation or framework, where an existing certification does not exist (e.g., NIST CSF 2.0 certification). The SCF CAP is designed for cybersecurity & privacy practitioners by cybersecurity & data privacy practitioners. This concept is based on the need within the industry for a tailored conformity assessment solution that is capable of addressing several key considerations:
View compliance as a natural by-product of secure practices;
Scale to address multifaceted operational requirements (e.g., laws, regulations and frameworks);
Acknowledge the stated risk tolerance of the OSC since not all organizations have the same risk tolerance;
Minimize the risk of “gaming” the certification process that provides no useful insights into the security posture of the Organization Seeking Certification (OSC);
Utilize technology to make the assessment process more efficient to drive down labor-related assessment costs; and
Leverage existing industry recognized practices, where possible.
The SCF CAP is designed to utilize tailored cybersecurity and data privacy controls to specifically address the applicable statutory, regulatory and contractual obligations an organization needs to comply with. The metaframework nature of the SCF enables an organization to perform a conformity assessment that can span multiple cybersecurity and data privacy-specific laws, regulations and frameworks.
Secure Controls Framework (SCF) "Premium Content" - Editable Policies, Control Objectives, Standards, Guidelines, Controls & Metrics.
Product Walkthrough Video
When you click the image or the link below, it will direct you to a different page on...
NIST Cybersecurity Framework 2.0 (NIST CSF 2.0) Policy Template - Editable Policies & Standards
Product Walkthrough Video
When you click the image or the link below, it will direct you to a different page on our website that contains a short...
Cybersecurity Standardized Operating Procedures (CSOP) DSP | SCF Version
Product Walkthrough Video
When you click the image or the link below, it will direct you to a different page on our website that contains a short product walkthrough...
Cybersecurity Standardized Operating Procedures (CSOP) NIST Cybersecurity Framework 2.0
Product Walkthrough Video
When you click the image or the link below, it will direct you to a different page on our website that contains a short...
Cybersecurity & Data Protection Program (CDPP) Bundle #1A - NIST CSF 2.0 (20% discount)
This is a bundle that includes the following two (2) ComplianceForge products that are focused on operationalizing the NIST Cybersecurity...
Cybersecurity & Data Protection Program (CDPP) Bundle #2 (30% discount)
Is your organization looking for enterprise-class NIST Cybersecurity Framework policy, standard & procedure documentation? This is a bundle that includes the following ten...
Cybersecurity Supply Chain Risk Management (C-SCRM) Bundle #2 - DSP Version (45% discount)
This is a bundle that includes the following thirteen (13) ComplianceForge products that are focused on operationalizing Cybersecurity Supply Chain Risk...
Digital Security Plan (DSP) Bundle #1 - SCF-Aligned Policies, Standards & Procedures (25% Discount)
Is your organization looking for enterprise cybersecurity documentation? This is a bundle that includes the following two (2) ComplianceForge...
Digital Security Plan (DSP) Bundle #2 - ENHANCED DIGITAL SECURITY (35% Discount)
Is your organization looking ofr enterprise cybersecurity documentation? This is a bundle that includes the following seven (7) ComplianceForge products that are...
Digital Security Plan (DSP) Bundle #3 - ROBUST DIGITAL SECURITY (45% Discount)
Is your organization looking for enterprise cybersecurity documentation? This is a bundle that includes the following thirteen (13) ComplianceForge products that are...
NIST 800-171 & CMMC 2.0 Compliance Bundle #4 - EXPERT CMMC 2.0 Levels 1-3 (45% discount)
Is your organization looking to achieve CMMC compliance? This is a bundle that includes the following thirteen (13) ComplianceForge...
Privacy Bundle #2 - DSP Version (45% discount)
This is a bundle that includes the following twelve (12) ComplianceForge products that are focused on operationalizing the cybersecurity and privacy principles:
Digital Security Program (DSP)
Cybersecurity...