Subissues
| Summary | Description |
|---|---|
| Loss of revenue | A negative impact on the ability to generate revenue (e.g., a loss of clients or an inability to generate future revenue). |
| Cancelled contract | A cancelled contract with a client or other entity for cause (e.g., failure to fulfill obligations for secure practices). |
| Diminished competitive advantage | Diminished competitive advantage (e.g., lose market share, internal dysfunction, etc.). |
| Diminished reputation | Diminished brand value (e.g., tarnished reputation). |
| Fines and judgements | Financial damages due to fines and/or judgements from statutory / regulatory / contractual non-compliance. |
| Unmitigated vulnerabilities | Unmitigated technical vulnerabilities that lack compensating controls or other mitigation actions. |
| System compromise | A compromise of a system, application or service that affects confidentiality, integrity, availability and/or safety. |
- Secure Controls Framework -
The Secure Controls Framework® (SCF)
"The SCF is the Common Controls Framework™ (CCF), the world's most comprehensive cybersecurity and data privacy metaframework - it is also free to use. The entire concept is building secure, compliant and resilient capabilities in the most efficient and cost-effective manner possible.
The SCF is more than just a unified control catalog, since its included content creates a playbook for Governance, Risk & Compliance (GRC) capabilities. Used globally by organizations of every size, the SCF is a robust and scalable solution for security, compliance and resilience controls. As a comprehensive security framework, the SCF maps 1,400+ controls across 200+ laws, regulations, and industry frameworks so you can implement once and comply everywhere.
Like it or not, cybersecurity is a protracted war on an asymmetric battlefield, where the threats are everywhere and as defenders we have to make the effort to work together to help improve cybersecurity and data privacy practices, since we all suffer when massive data breaches occur or when cyber attacks have physical impacts. Hackers share information on attack methods with other hackers, so why shouldn’t the good guys share information on how to best protect an organization? We decided to take action and make a difference, since we feel it is too important to wait for someone else to fix the problems that exist.
The SCF is made up of volunteers, mainly specialists within the cybersecurity profession, who focus on GRC and the cybersecurity side of data privacy. These are auditors, engineers, architects, incident responders, consultants and other specialists who live and breathe these topics on a daily basis. The end product is "expert-derived content" that makes up the SCF." https://securecontrolsframework.com/Terms & Conditions
The SCF End User License Agreement (EULA) governs the use of the Secure Controls Framework® (SCF) under the Creative Commons Attribution-No Derivatives 4.0 International Public License.