Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

Security, Compliance & Resilience (SCR) Principles

The SCR establishes 34 common-sense principles to guide the development and oversight of a modern security and privacy program, operationalizing security & privacy by design. The SCR Principles simplify the concept of security and privacy by design into actionable guidance for building and overseeing a modern cybersecurity program.

Key Takeaways - Security, Compliance & Resilience (SCR) Principles
  • The SCR establishes 34 common-sense principles organized by SCF control domains.
  • These principles guide security & privacy by design, embedding protections from the start, not bolting them on after.
  • Each principle maps to SCF controls that can operationalize it with specific, actionable requirements.
  • ComplianceForge's SCRP product provides pre-built documentation aligned to these principles.
Security & Privacy By Design

What Are Secure, Compliant & Resilient Principles?

The SCR principles are sourced from the Secure Controls Framework (SCF), which is a free resource. The SCF's comprehensive listing of over 1,500 cybersecurity and data privacy controls is categorized into 34 domains that are mapped to over 200 statutory, regulatory, and contractual frameworks. Those applicable SCF controls can operationalize the SCR principles to help an organization ensure that secure practices are implemented by design and by default.

Each of the 34 SCF domains has a corresponding SCR principle that defines the overarching goal for that domain. This creates a clear line from principle to control to implementation, ensuring nothing falls through the cracks.

Organized By SCF Domain

The 34 Domain Principles

The SCR establishes 34 common-sense principles to guide the development and oversight of a modern security and privacy program. The SCR is sourced from the SCF, which is a free resource for businesses. The SCF’s free, comprehensive listing of over 1,500 cybersecurity and data privacy controls is categorized into 34 domains that are mapped to over 200 statutory, regulatory and contractual frameworks. Those applicable SCF controls can operationalize the SCR principles to help an organization ensure that secure practices are implemented by design and by default.

ComplianceForge's Security, Compliance & Resilience Program (SCRP) can help you operationalize these security & privacy principles:

Secure Controls Framework (SCF) domains example
From Principles To Practice

Operationalizing SCR Principles

Principles without implementation are just words. The SCF provides the controls, and ComplianceForge provides the documentation to make them actionable.

The path from principle to practice follows a clear hierarchy. SCR Principles define the what at the highest level, SCF Controls define the specific safeguards needed, and ComplianceForge documentation provides the policies, standards, and procedures that operationalize those controls in your organization.

This approach ensures that security and privacy are not afterthoughts but are embedded into every aspect of your organization's technology, processes, and culture from the beginning.

Common Questions

Frequently-Asked Questions

Here are answers to common questions about the SCR principles:

What does SCR stand for in cybersecurity?
In the context of the Secure Controls Framework (SCF), SCR stands for Security, Compliance & Resilience, which reflects the goal of being secure, compliant, and resilient at the same time. The term appears across SCF resources, including the SCR principles, the SCR-RMM risk management model, and the SCR-CMM capability maturity model. Each of these resources treats controls as the foundation for achieving all three outcomes.
How many SCR principles are there?
There are 34 SCR principles, one for each of the 34 domains in the Secure Controls Framework (SCF). Each principle defines the overarching goal for its domain, such as governance, asset management, incident response, or third-party management. The SCF controls within that domain then provide specific, actionable requirements to achieve the principle. This creates a direct line from a high-level principle to the controls and documentation that put it into practice.
What is security and privacy by design?
Security and privacy by design means building protections into systems, applications, processes, and services from the start instead of adding them after deployment. The SCR principles support this by defining what good looks like in each Secure Controls Framework (SCF) domain, so security and privacy requirements are considered from the beginning of a project. The goal is for secure practices to be implemented by design and by default, with compliance becoming a natural byproduct.
How do you put SCR principles into practice?
You put SCR principles into practice by moving from principle to control to documentation. Each principle defines what should be achieved at the highest level for a Secure Controls Framework (SCF) domain, and the SCF controls in that domain define the specific safeguards needed. Policies, standards, and procedures then turn those controls into requirements and tasks your people can follow. For a head start, the ComplianceForge Security, Compliance & Resilience Program (SCRP) gives you pre-built documentation aligned to these principles.
What is the SCR principle for cybersecurity governance?
The SCR principle for governance is to govern the organization's Security, Compliance & Resilience Program (SCRP) through accountable oversight, evidence-based decision-making, and defensible evidence that the organization is secure, compliant, and resilient. It belongs to the Security, Compliance & Resilience Governance (GOV) domain of the Secure Controls Framework (SCF). This principle is what drives documented policies, assigned accountability, and metrics that leadership can rely on.