Secure, Compliant & Resilient Risk Management Model (SCR-RMM)

The Secure, Compliant & Resilient Risk Management Model (SCR-RMM) is built directly into the Secure Controls Framework (SCF). The concept of creating the SCR-RMM was to create an efficient methodology to identify, assess, report and mitigate risk. This project was approached from the perspective of asking the question, “How should I management risk?” and was a collaboration between ComplianceForge and the SCF. The SCR-RMM takes a holistic approach to controls, risks and threats as a way to reduce or eliminate the traditional Fear, Uncertainty and Doubt (FUD) that makes many risk assessments meaningless. The SCR-RMM is free to use and is licensed under the Creative Commons licensing model.

cybersecurity & data Privacy Risk Management Model

Cybersecurity Risk Management Requirements

All organizations have a need to manage risk. Most organizations are compelled to management risk and these requirements come from a broad range of statutory, regulatory and contractual origins. Regardless of your industry, requirements to manage cybersecurity risk exist and failing to manage risk could leave your organization exposed to liabilities from non-compliance:

In risk management, the old adage of “the path to hell is paved with good intentions” is very applicable. The reason for this is all too often, risk management personnel are tasked with generating risk assessments and creating the questions to ask in those assessments without having a centralized set of organization-wide cybersecurity and privacy controls to work from. This generally leads to risk teams making up risks and asking questions that are not supported by the organization’s policies and standards. For example, an organization is an “ISO shop” that operates an ISO 27002-based Information Security Management System (ISMS) to govern its policies and standards, but its risk team is asking questions about NIST SP 800-53 or 800-171 controls that are not applicable to the organization. This scenario of “making up risks” points to a few security program governance issues:

SCF cybersecurity & data Privacy Risk management Model

SCR-RMM: Applicability To NIST 800-171 & CMMC

An immediate need for many organizations is compliance with NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC). The SCR-RMM is a tool that can be used to address the following NIST SP 800-171 requirements:

Browse Our Products

  • Secure Controls Framework (SCF) Policy, Standards, Controls & Metrics Template - SCRP

    Policies & Standards - Secure Controls Framework (SCF)

    Secure Controls Framework (SCF)

    Secure Controls Framework (SCF)-Based Policies, Control Objectives, Standards, Guidelines, Controls & Metrics ComplianceForge is a Licensed Content Provider (LCP) by the Secure Controls Framework (SCF). This means ComplianceForge is authorized to...

    $10,400.00
    Choose Options
  • Procedures Template - SCRP

    Procedures - Secure Controls Framework (SCF)

    Secure Controls Framework (SCF)

    Cybersecurity Standardized Operating Procedures (CSOP)  SCRP Version Product Walkthrough Video When you click the image or the link below, it will direct you to a different page on our website that contains a short product walkthrough video...

    $6,400.00
    Choose Options
  • ComplianceForge - NIST 800-171 & CMMC NIST 800-171 Compliance Program (NCP): CMMC Level 2

    NIST 800-171 Compliance Program (NCP)

    ComplianceForge - NIST 800-171 & CMMC

    NIST 800-171 Rev 2 & Rev 3 / CMMC 2.0 Compliance Made Easier! The NCP is editable & affordable cybersecurity documentation to address your NIST 800-171 R2 / R3 and CMMC 2.0 Levels 1-2 compliance needs. When you click the image or the link...

    $8,950.00
    $5,300.00
    $5,200.00
    Choose Options
  • Secure Controls Framework (SCF) Bundle 1: Policies, Standards, Procedures & Controls

    SCF Policies, Standards, Procedures & Metrics

    Secure Controls Framework (SCF)

    Secure Controls Framework (SCF) Bundle #1 - SCF-Aligned Policies, Standards & Procedures (25% Discount) Is your organization looking for enterprise cybersecurity documentation? This is a bundle that includes the following two (2) ComplianceForge...

    $16,800.00
    $16,800.00
    $12,600.00
    Choose Options
  • Secure Controls Framework (SCF) Bundle 3: Robust Security Documentation

    SCF Documentation Solution

    Secure Controls Framework (SCF)

    Secure Controls Framework (SCF) Bundle #2 - ROBUST DIGITAL SECURITY (45% Discount) Is your organization looking for enterprise cybersecurity documentation? This is a bundle that includes the following thirteen (13) ComplianceForge products that are...

    $27,412.00 - $32,212.00
    Choose Options
  • ComplianceForge C-SCRM Bundle 2: DSP version (SCF alignment)

    C-SCRM Bundle 2: DSP version (SCF alignment)

    ComplianceForge

    Cybersecurity Supply Chain Risk Management (C-SCRM) Bundle #2 - DSP Version (45% discount) This is a bundle that includes the following thirteen (13) ComplianceForge products that are focused on operationalizing Cybersecurity Supply Chain Risk...

    $49,840.00
    $49,840.00
    $27,410.00
    Choose Options
  • Secure Controls Framework (SCF) CMMC Bundle 4: Levels 1-3 (DSP & SCF)

    CMMC Bundle 4: Levels 1-3 (DSP & SCF)

    Secure Controls Framework (SCF)

    NIST 800-171 & CMMC 2.0 Compliance Bundle #4 - EXPERT  CMMC 2.0 Levels 1-3  (45% discount) Is your organization looking to achieve CMMC compliance? This is a bundle that includes the following thirteen (13) ComplianceForge...

    $47,490.00
    $47,490.00
    $26,120.00
    Choose Options
  • ComplianceForge Privacy Bundle 2: DSP version (SCF alignment)

    Privacy Bundle 2: DSP version (SCF alignment)

    ComplianceForge

    Privacy Bundle #2 - DSP Version (45% discount) This is a bundle that includes the following twelve (12) ComplianceForge products that are focused on operationalizing the cybersecurity and privacy principles: Digital Security Program (DSP) Cybersecurity...

    $45,605.00
    $45,605.00
    $25,083.00
    Choose Options