About the Secure Controls Framework

How SCF powers cross-mapping across the platform

The Secure Controls Framework (SCF) is the cross-mapping spine that ties a regulation to a control, to the technical checks that satisfy it, and to the work role responsible for the fix. Across our platform, every cross-mapping you see comes from SCF, is credited to SCF, and carries the SCF version it was sourced from.

What SCF gives our subscribers

  • A unified control catalog of 1,534 controls across 34 cybersecurity and data privacy domains, already cross-referenced to NIST 800-53, ISO 27001, CIS, HIPAA, PCI DSS, FedRAMP, and 100+ other frameworks.
  • STRM relationship semantics preserved. We carry the SCF relationship type and its numeric weight together. We do not flatten “Intersects With (8)” and “Intersects With (3)” into the same thing. The weight is load-bearing.
  • Methodology that is auditable. Every mapping shows its SCF relationship type and version. If we display an alternate label set, it is a lossless relabel of the underlying STRM data, with the SCF relationship + weight stored beneath as the source of truth.

How SCF is credited across the product

  • Credit on every mapping. SCF cannot be displayed without its credit and version. The “Source: SCF 2026.2” badge appears alongside the data itself, not buried in a footer.
  • A first-class section in our navigation. The Secure Controls Framework has its own catalog, its own detail pages, and this About page, reachable from the sidebar.
  • Credit on every export. Any SCF data leaving our product as JSON, CSV, Excel, or via API carries the SCF version and a link back to securecontrolsframework.com.

The walk SCF makes possible

A user can start at a regulatory obligation, click to the SCF control that covers it, step from there to NIST 800-53, walk down to the CCIs, land on the STIG checks that implement them, and end on the NICE work role plus O*NET occupation that owns the fix. Or run the same walk in reverse, from a single STIG finding up to every regulation it helps satisfy. SCF is the connector that lights up the front half of that journey.

Partnership and licensing

The Secure Controls Framework is free and open to use. SCF content is shown here with attribution, not resold: every mapping credits SCF as the methodology, with the SCF reference and version stored alongside it. There is no charge to view SCF data on STIGViewer.

Source & methodology

The control catalog, cross-mappings, and STRM relationship data are provided by the Secure Controls Framework (SCF), 2026.2. © SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. Learn more at securecontrolsframework.com.

SCF

Powered by the Secure Controls Framework

The control catalog, cross-mappings, and STRM relationship data on the subscriber catalog and control detail pages are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.

© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com