Skip to content

Framework Management

The SCF Controls Platform provides powerful tools for managing compliance frameworks: the Control Library, the Mapping Matrix, and Scope by Framework bulk scoping.

The Scope by Framework feature allows you to bulk-scope all controls mapped to one or more compliance frameworks with a single action. This is the fastest way to build your control baseline when adopting a new framework.

  1. Navigate to Control Scoping (checkbox icon in sidebar)
  2. Click the Scope by Framework button in the sidebar
  3. The Framework Selection Modal opens showing all 260+ available frameworks
  4. Select one or more frameworks you need to comply with
  5. Preview shows how many controls will be added
  6. Click Add to Scope to bulk-scope all mapped controls
FeatureDescription
Multi-selectSelect multiple frameworks at once (e.g., ISO 27001 + SOC 2)
Preview countsSee exactly how many controls will be added before confirming
Additive onlyNever overwrites existing selections — only adds new controls
DeduplicationControls mapped to multiple frameworks are only added once
Selection reasonAutomatically records why controls were scoped

Scenario: Your organization needs to comply with both ISO 27001:2022 and PCI DSS v4.0.

  1. Open Control Scoping
  2. Click Scope by Framework
  3. Select “ISO/IEC 27001:2022” and “PCI DSS v4.0.1”
  4. Preview shows: “316 controls from ISO 27001 + 364 controls from PCI DSS = 412 unique controls to add (268 overlap)”
  5. Click Add to Scope
  6. All 412 unique controls are now in scope with implementation status “Not Started”

The Control Library is your reference for browsing all 1,451 SCF controls. Access it by clicking the Book icon in the sidebar.

The Control Library uses a split-panel layout:

Left Panel — Control List

  • Stats header — Shows filtered count vs. total controls
  • Search bar — Filter by control ID, name, description, or domain
  • Filters dropdown — Filter by domain, NIST CSF function, or control weight
  • Control cards — Each displays ID, name, badges, domain, artifact count, and framework count

Right Panel — Control Details

When you select a control, the detail panel shows:

SectionContent
HeaderControl ID, name, domain, NIST CSF function
DescriptionFull control description
Control QuestionAssessment question for the control
Maturity RoadmapC|P-CMM guidance for each maturity level (0-5)
Business Size GuidanceImplementation guidance by organization size
Related ArtifactsEvidence items required
Framework MappingsWhich frameworks this control satisfies
Risk & Threat ContextAssociated risks and threats

Search across multiple fields simultaneously:

  • Control ID (e.g., “GOV-01”)
  • Control name (e.g., “access review”)
  • Description text
  • Domain name

Filter by specific attributes using the collapsible Filters dropdown:

FilterOptions
Domain32 SCF domains (AST, BCR, CFG, CRY, etc.)
NIST CSF FunctionIdentify, Protect, Detect, Respond, Recover, Govern
Control Weight0 (Minimal) to 10 (Critical)

Each control card displays:

  • SCF ID badge — Unique identifier (e.g., GOV-01)
  • NIST CSF function pill — Color-coded: Identify (blue), Protect (green), Detect (amber), Respond (red), Recover (purple), Govern (gray)
  • Control weight badge — Importance rating 0-10
  • Control name — Brief description of the control
  • Domain — Control category
  • Metadata — Artifact count and framework count

The Mapping Matrix visualizes how SCF controls map to compliance frameworks. Access it by clicking the Grid icon in the sidebar.

The matrix displays:

  • Rows — SCF controls (ID and name)
  • Columns — Compliance frameworks (ISO 27001, SOC 2, NIST, etc.)
  • Cells — An “X” indicates the control maps to that framework

Hover over any “X” to see the tooltip showing:

  • SCF control ID
  • Framework name
  • Specific requirement references (e.g., “A.9.1.1”, “CC6.1”)
ControlFunction
Legend buttonShow/hide implementation status color guide
Show scoped onlyFilter to only display controls you’ve selected
StatsShows control count and framework count

When you have scoped controls, the matrix rows are color-coded by implementation status:

ColorStatus
GreenImplemented
BlueIn Progress
GrayNot Started
Orange/RedAt Risk
Light GrayNot Applicable
YellowDeferred

Click the Legend button to see the full color guide.


The platform includes mappings to 260+ compliance frameworks from the Secure Controls Framework (SCF). This comprehensive coverage spans government, industry, and international standards.

The platform supports frameworks across these categories:

US Federal & Government

  • NIST SP 800-53 (R4 and R5, all baselines)
  • FedRAMP (R4, R5, High/Moderate/Low/Tailored)
  • NIST SP 800-171 (R2 and R3)
  • NIST Cybersecurity Framework v2.0
  • CMMC 2.0 (all levels)
  • CJIS Security Policy
  • IRS 1075
  • MARS-E 2.0

Industry Standards

  • PCI DSS v4.0.1 (all SAQ types)
  • SOC 2 (AICPA Trust Services Criteria)
  • HIPAA Security Rule
  • Cloud Controls Matrix (CCM) v4
  • CIS Controls v8.1
  • COBIT 2019

International Standards

  • ISO/IEC 27001:2022
  • ISO/IEC 27002:2022
  • ISO/IEC 27017:2015 (Cloud)
  • ISO/IEC 27018:2019 (Privacy)
  • ISO/IEC 27701:2025 (Privacy)
  • ISO/IEC 42001:2023 (AI)
  • ISO 22301:2019 (Business Continuity)

European Frameworks

  • EU NIS2 Directive
  • EU DORA (Digital Operational Resilience)
  • EU AI Act
  • BSI Standard 200-1
  • Cloud Computing Compliance Criteria (C5)
  • ENS (Spain National Security Scheme)

Asia-Pacific Frameworks

  • Australian ISM (June 2024)
  • New Zealand NZISM v3.6
  • Japan ISMAP
  • Singapore MAS TRM
  • Korea FSI Guidelines

Specialized Frameworks

  • NIST AI RMF 1.0
  • NIST SP 800-161 R1 (Supply Chain)
  • NIST SP 800-82 (ICS/OT Security)
  • TISAX ISA 6 (Automotive)
  • MPA Content Security v5.1 (Media)
  • NERC CIP 2024 (Energy)
FrameworkMapped Controls
NIST SP 800-53 R5777
NIST SP 800-53 R4652
IRS 1075445
GovRAMP High441
FedRAMP R5 High423
SOC 2 (TSC 2022)412
NIST SP 800-171 R3408
PCI DSS v4.0.1364
ISO/IEC 27002:2022316
NIST CSF v2.0253

  1. Open Control Scoping
  2. Click Scope by Framework
  3. Select your target framework(s)
  4. Review the preview count
  5. Click Add to Scope
  6. Your baseline is established with all required controls
  1. Use Scope by Framework to select all required frameworks
  2. Open the Mapping Matrix to see coverage overlap
  3. Focus implementation on controls that satisfy multiple frameworks
  4. Use the matrix to verify complete coverage
  1. Open the Mapping Matrix
  2. Enable Show scoped only
  3. Find your target framework column
  4. Verify all controls show “X” marks (coverage)
  5. Check implementation status colors are green (implemented)
  1. Open the Mapping Matrix
  2. Identify framework columns with missing “X” marks
  3. Click on controls to view details
  4. Use Scope by Framework to add missing controls

  1. Use Scope by Framework first — Bulk-scope your primary framework
  2. Layer additional frameworks — Add secondary frameworks incrementally
  3. Review overlaps — Use the Mapping Matrix to understand multi-framework controls
  4. Prioritize by weight — Focus on high-weight controls (8-10) first
  1. Check the Matrix regularly — Verify coverage as frameworks are updated
  2. Review new SCF releases — As SCF adds controls, assess relevance
  3. Document decisions — Use selection reasons in Control Scoping