scf authorized content provider compliance forge

ComplianceForge Is A SCF Licensed Content Provider (SCF LCP)

ComplianceForge is a Licensed Content Provider (LCP) by the SCF. This means ComplianceForge is authorized to sell cybersecurity and data protection policies, standards and procedures based on SCF controls.

SCF Licensed Content Provider

Why ComplianceForge and the Secure Controls Framework (SCF) Should Be Used for Cybersecurity Documentation

The Secure Controls Framework (SCF) is a meta-framework that maps to over 100 cybersecurity and data privacy laws, regulations, and industry frameworks (e.g., NIST, ISO, GDPR, HIPAA, PCI DSS), and ComplianceForge offers structured, comprehensive, and efficient solutions based on the SCF for developing and managing cybersecurity documentation. This combination helps organizations streamline compliance efforts, manage risks effectively, and build a robust digital security program tailored to their specific needs and regulatory obligations. ComplianceForge and the SCF are highly beneficial for cybersecurity documentation for several reasons, derived from their design principles and features:

Efficiency and Time Savings

Enhanced Cybersecurity Compliance and Risk Management

Clarity and Communication

What SCF-Based Documentation Does ComplianceForge Sell?

ComplianceForge offers the following SCF-based documentation templates:

  1. Digital Security Program (DSP)
    • An enterprise-class solution for SCF-based policies, control objectives, standards, guidelines, metrics and more.
    • Provides complete coverage for all SCF controls.
    • All SCF-based policies map 1-1 with SCF domains.
    • All SCF-based standards map 1-1 with SCF controls
    • Comes in both Word and Excel formats, so the DSP can be imported into a GRC platform that accepts policies and standards.
  2. Cybersecurity Standardized Operating Procedures (CSOP)
    • Provides SCF-based procedures that compliment the standards within the DSP.
    • Provides complete coverage for all SCF controls.
    • All procedures map 1-1 with SCF controls.
    • Comes in both Word and Excel formats, so the CSOP can be imported into a GRC platform that accepts procedures.
  3. NIST 800-171 Compliance Program (NCP)
    • Tailored for NIST 800-171 & CMMC L1-L2
    • Provides SCF-based policies specific to NIST 800-171 and CMMC 2.0 L2).
    • Provides SCF-based standards that are specific to NIST 800-171 and CMMC 2.0 L2).
    • Provides SCF-based procedures that are specific to NIST 800-171 and CMMC 2.0 L2).
    • Includes a NIST 800-161 R1-based Supply Chain Risk Management (SCRM) Plan.
    • Includes a Risk Assessment Worksheet & Report Template (perform a risk & threat assessment using Microsoft Word and Excel).
    • Includes a System Security Plan (SSP) Template.
    • Includes a Plan of Action & Milestones (POA&M) Template.
    • And includes more!
  4. NIST Cybersecurity Framework 2.0 (NIST CSF 2.0) Policies & Standards
    • Tailored for NIST CSF 2.0.
    • Provides SCF-based policies to address NIST CSF 2.0 requirements.
    • Provides SCF-based standards to address NIST CSF 2.0 requirements.
  5. NIST CSF 2.0 Procedures
    • Tailored for NIST CSF 2.0.
    • Provides SCF-based procedures to address NIST CSF 2.0 requirements.
  6. ISO 27001/27002 Policies & Standards
    • Tailored for ISO 27001:2022 and ISO 27002:2022.
    • Provides SCF-based policies to address ISO 27001:2022 and ISO 27002:2022 controls.
    • Provides SCF-based standards to address ISO 27001:2022 and ISO 27002:2022 controls.
  7. ISO 27001/27002 Procedures
    • Tailored for ISO 27001:2022 and ISO 27002:2022.
    • Provides SCF-based procedures to address ISO 27001:2022 and ISO 27002:2022 controls.

ComplianceForge also offers multiple discounted bundles, so please take a look and see if any of our bundles can help your organization! If there are specific products you want, you can create your own custom bundle by adding the products to your cart, submitting a quote, and we will work with you to get the best discount!

Example SCF Policies, Standards & Procedures.

The ComplianceForge Reference Model establishes how cybersecurity and data privacy documentation is meant to be built. This documentation model that leverages industry-recognized terminology to logically arrange these documentation components into their rightful order. This model creates an approach to architecting documentation that is concise, scalable and comprehensive. When that is all laid out properly, an organization's cybersecurity and data protection documentation should be hierarchical and linked from policies all the way through metrics. The swimlane diagram shown below (click for a larger PDF) defines the terminology and demonstrates the linkages between these various documentation components.

complianceforge reference model - hierarchical cybersecurity governance framework 

Cybersecurity & data protection documentation needs to usable. This means the documentation needs to be written clearly, concisely and in a business-context language that users can understand. By doing so, users will be able to find the information they are looking for and that will lead to IT security best practices being implemented throughout your company. Additionally, having good cybersecurity documentation can be “half the battle” when preparing for an audit, since it shows that effort went into the program and key requirements can be easily found.

The PDF document shown below provides two, side-by-side examples from policies all the way through metrics, so you can see what the actual content looks like.

example scf policies standards procedures templates

 

Browse Our Products

  • Secure Controls Framework (SCF) Policy, Standards, Controls & Metrics Template - DSP / SCF

    Digital Security Program (DSP)

    Secure Controls Framework (SCF)

    Secure Controls Framework (SCF) "Premium Content" - Editable Policies, Control Objectives, Standards, Guidelines, Controls & Metrics. Product Walkthrough Video When you click the image or the link below, it will direct you to a different page on...

    $10,400.00 - $15,200.00
    Choose Options
  • ComplianceForge NIST Cybersecurity Framework Compliance Documentation Templates Policy & Standards Template - NIST CSF 2.0

    Policy & Standards Template - NIST CSF 2.0

    ComplianceForge NIST Cybersecurity Framework Compliance Documentation Templates

    NIST Cybersecurity Framework 2.0 (NIST CSF 2.0) Policy Template - Editable Policies & Standards  Product Walkthrough Video When you click the image or the link below, it will direct you to a different page on our website that contains a short...

    $1,980.00 - $6,780.00
    Choose Options
  • Secure Controls Framework (SCF) Procedures Template - DSP / SCF

    Procedures Template - DSP / SCF

    Secure Controls Framework (SCF)

    Cybersecurity Standardized Operating Procedures (CSOP)  DSP | SCF Version Product Walkthrough Video When you click the image or the link below, it will direct you to a different page on our website that contains a short product walkthrough...

    $6,400.00 - $11,200.00
    Choose Options
  • ComplianceForge Procedures Template - NIST CSF 2.0

    Procedures Template - NIST CSF 2.0

    ComplianceForge

    Cybersecurity Standardized Operating Procedures (CSOP)   NIST Cybersecurity Framework 2.0  Product Walkthrough Video When you click the image or the link below, it will direct you to a different page on our website that contains a short...

    $4,700.00 - $9,500.00
    Choose Options
  • ComplianceForge NIST Cybersecurity Framework Compliance Documentation Templates Policies & Procedures Bundle - NIST CSF 2.0

    Policies & Procedures Bundle - NIST CSF 2.0

    ComplianceForge NIST Cybersecurity Framework Compliance Documentation Templates

    Cybersecurity & Data Protection Program (CDPP) Bundle #1A -  NIST CSF 2.0   (20% discount) This is a bundle that includes the following two (2) ComplianceForge products that are focused on operationalizing the NIST Cybersecurity...

    $5,344.00 - $10,144.00
    Choose Options
  • ComplianceForge NIST Cybersecurity Framework Compliance Documentation Templates Compliance Templates - NIST CSF 2.0

    Compliance Templates - NIST CSF 2.0

    ComplianceForge NIST Cybersecurity Framework Compliance Documentation Templates

    Cybersecurity & Data Protection Program (CDPP) Bundle #2 (30% discount) Is your organization looking for enterprise-class NIST Cybersecurity Framework policy, standard & procedure documentation? This is a bundle that includes the following ten...

    $20,353.00 - $25,153.00
    Choose Options
  • ComplianceForge C-SCRM Bundle 2: DSP version (SCF alignment)

    C-SCRM Bundle 2: DSP version (SCF alignment)

    ComplianceForge

    Cybersecurity Supply Chain Risk Management (C-SCRM) Bundle #2 - DSP Version (45% discount) This is a bundle that includes the following thirteen (13) ComplianceForge products that are focused on operationalizing Cybersecurity Supply Chain Risk...

    $27,412.00 - $32,212.00
    Choose Options
  • Secure Controls Framework (SCF) DSP Bundle 1: Policies, Standards, Procedures & Controls

    DSP Bundle 1: Policies, Standards, Procedures & Controls

    Secure Controls Framework (SCF)

    Digital Security Plan (DSP) Bundle #1 - SCF-Aligned Policies, Standards & Procedures (25% Discount) Is your organization looking for enterprise cybersecurity documentation? This is a bundle that includes the following two (2) ComplianceForge...

    $12,600.00 - $17,400.00
    Choose Options
  • Secure Controls Framework (SCF) DSP Bundle 2: Enhanced Digital Security Documentation

    DSP Bundle 2: Enhanced Digital Security Documentation

    Secure Controls Framework (SCF)

    Digital Security Plan (DSP) Bundle #2 - ENHANCED DIGITAL SECURITY (35% Discount) Is your organization looking ofr enterprise cybersecurity documentation? This is a bundle that includes the following seven (7) ComplianceForge products that are...

    $19,165.00 - $23,965.00
    Choose Options
  • Secure Controls Framework (SCF) DSP Bundle 3: Robust Digital Security Documentation

    DSP Bundle 3: Robust Digital Security Documentation

    Secure Controls Framework (SCF)

    Digital Security Plan (DSP) Bundle #3 - ROBUST DIGITAL SECURITY (45% Discount) Is your organization looking for enterprise cybersecurity documentation? This is a bundle that includes the following thirteen (13) ComplianceForge products that are...

    $27,412.00 - $32,212.00
    Choose Options
  • Secure Controls Framework (SCF) CMMC Bundle 4: Levels 1-3 (DSP & SCF)

    CMMC Bundle 4: Levels 1-3 (DSP & SCF)

    Secure Controls Framework (SCF)

    NIST 800-171 & CMMC 2.0 Compliance Bundle #4 - EXPERT  CMMC 2.0 Levels 1-3  (45% discount) Is your organization looking to achieve CMMC compliance? This is a bundle that includes the following thirteen (13) ComplianceForge...

    $26,120.00 - $30,920.00
    Choose Options
  • ComplianceForge Privacy Bundle 2: DSP version (SCF alignment)

    Privacy Bundle 2: DSP version (SCF alignment)

    ComplianceForge

    Privacy Bundle #2 - DSP Version (45% discount) This is a bundle that includes the following twelve (12) ComplianceForge products that are focused on operationalizing the cybersecurity and privacy principles: Digital Security Program (DSP) Cybersecurity...

    $25,083.00 - $26,433.00
    Choose Options