SCF Assessor Syllabus

You can download the SCF Assessor syllabus from: https://securecontrolsframework.com/content/syllabus/scf-assessor.pdf

Flexible Learning
Computer Based Training (CBT) to learn at your own pace on your own equipment.

Curriculum-Based Training
SCF-approved curriculum to support a role in the SCF CAP Ecosystem on a 3PAO's assessment team.
%20-%20white.png)
SCF Certification
Valuable certification to participate in the SCF CAP Ecosystem.
About The SCF Assessor Course
SCF Assessors are SAICO-certified individuals who are qualified to participate in and/or lead a SCF 3PAO’s assessment team. SCF Assessors are required to undergo foundational training (this course) to help ensure success in the role of an SCF Assessor. SCF Assessor training prepares students to participate on a SCF Third-Party Assessment Organization’s (3PAO) assessment team to conduct SCF-related Third Party Assessment, Attestation and Certification Services (3PAAC Services). The SCF Assessor course is not designed to train students to think like an assessor/auditor, since that is a prerequisite skill. The SCF Assessor training course is designed to refine a student’s existing knowledge of the following core concepts: 1. The structure and content of: a. Secure Controls Framework (SCF); and b. SCF Conformity Assessment Program (SCF CAP); 2. The assessment standards used to perform SCF CAP assessments; 3. Scoping the assessment using the Unified Scoping Guide (USG); 4. Cybersecurity risk tolerance & materiality concepts; and 5. The SCF CAP Code of Professional Conduct (CoPC). Prerequisites include having a proficient / conversational understanding of the following: o What the Secure Controls Framework (SCF) (e.g., structure, content, uses, etc.); o SCF Conformity Assessment Program (SCF CAP); o Cybersecurity & Data Protection Assessment Standards (CDPAS); o Integrated Controls Management (ICM) Model; o SCF Cybersecurity & Data Privacy Capability Maturity Model (C|P-CMM); o SCF Cybersecurity & Data Privacy Risk Management Model (C|P-RMM); o Unified Scoping Guide (USG); o Cybersecurity risk tolerance & materiality concepts; and o Proficient understanding of Set Theory Relationship Mapping (STRM). The SCF Assessor knowledge exam consists of one hundred (100) questions based on the course syllabus. A passing score of at least eighty percent (80%) is required to pass the knowledge exam and obtain certification as a SCF Assessor. SCF Assessor certifications are valid for a one (1) year period at which time, the certificate must be renewed or it is expired. The renewal process included paying a fee and taking a knowledge test to ensure the SCF Assessor's continued proficiency in the subject matter.
SCF Assessor Certification Is Valid For One Year
Once you earn your SCF Assessor certification, ongoing maintenance is $250/year (50% discount) to have a new badge/certificate issued.
$500.00
SFC Assessor Course Curriculum
-
1
SCF Assessor Overview
-
(Included in full purchase)
Course Overview & Knowledge Prerequisites
-
(Included in full purchase)
Education / Certification Prerequisites
-
(Included in full purchase)
-
2
Secure Controls Framework (SCF) Overview
-
(Included in full purchase)
What Is The SCF?
-
(Included in full purchase)
SCF Domains
-
(Included in full purchase)
SCF Components
-
(Included in full purchase)
SCF Structure Visualization
-
(Included in full purchase)
Assessment Objectives (AOs)
-
(Included in full purchase)
Evidence Request List (ERL)
-
(Included in full purchase)
SCF Cybersecurity & Data Privacy Risk Management Model (C|P-RMM)
-
(Included in full purchase)
SCF Cybersecurity & Data Privacy Capability Maturity Model (C|P-CMM)
-
(Included in full purchase)
Cybersecurity Maturity "Sweet Spot" Considerations
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
3
SCF Conformity Assessment Program (SCF CAP)
-
(Included in full purchase)
SCF CAP Ecosystem
-
(Included in full purchase)
SCF & Cyber AB Relationship
-
(Included in full purchase)
SCF CAP Body of Knowledge (SCF CAP BoK)
-
(Included in full purchase)
Control Designations
-
(Included in full purchase)
Conformity Designations (SCF CAP - Pass / Fail Results)
-
(Included in full purchase)
Conformity Designation - STRICTLY CONFORMS
-
(Included in full purchase)
Conformity Designation - CONFORMS
-
(Included in full purchase)
Conformity Designation - SIGNIFICANT DEFICIENCY
-
(Included in full purchase)
Conformity Designation - MATERIAL WEAKNESS
-
(Included in full purchase)
SCF CAP Assessment Guides
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
4
SCF STRM (Set Theory Relationship Mappings)
-
(Included in full purchase)
Set Theory Relationship Mapping (STRM) Overview
-
(Included in full purchase)
How Does The SCF Utilize STRM?
-
(Included in full purchase)
STRM Examples
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
5
Cybersecurity & Data Protection Assessment Standards (CDPAS)
-
(Included in full purchase)
Cybersecurity & Data Protection Assessment Standards (CDPAS)
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
6
SCF CAP Assessment Rigor
-
(Included in full purchase)
SCF CAP Assessment Rigor Overview
-
(Included in full purchase)
SCF CAP Sampling Guidance
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
7
SCF CAP Assessment Roles and Responsibilities
-
(Included in full purchase)
Organization Seeking Assessment (OSA)
-
(Included in full purchase)
SCF Assessors
-
(Included in full purchase)
SCF Third-Party Assessment Organizations (SCF 3PAOs)
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
8
Integrated Controls Management (ICM) Model
-
(Included in full purchase)
A "How To GRC" Playbook
-
(Included in full purchase)
Defining Mandatory vs Discretional Controls
-
(Included in full purchase)
People, Processes, Technology, Data & Facilities (PPTDF)
-
(Included in full purchase)
ICM Principles
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
9
Assessment Scoping Using The Unified Scoping Guide (USG)
-
(Included in full purchase)
Unified Scoping Guide (USG) Overview
-
(Included in full purchase)
Scoping Does Not Equal Applicability
-
(Included in full purchase)
Zone-Based Approach To Implementing Data-Centric Security Protections
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
10
SCF CAP Code of Professional Conduct (CoPC)
-
(Included in full purchase)
CoPC Principles
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
11
Performing Assessments Using SCF Connect
-
(Included in full purchase)
Assessment Workflow
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
12
SCF Connect - Single Source of Truth (SSOT)
-
(Included in full purchase)
SCF Connect Overview
-
(Included in full purchase)
Initiate An SCF CAP Assessment
-
(Included in full purchase)
Provision OSA User Accounts
-
(Included in full purchase)
Collect Required Assessment Evidence Using The SCF ERL
-
(Included in full purchase)
Conduct An SCF CAP Assessment
-
(Included in full purchase)
Assess Evidence Of Control Implementation
-
(Included in full purchase)
Generate SCF CAP Report On Conformity (RoC) Assessment Reports
-
(Included in full purchase)
End Of Chapter Review
-
(Included in full purchase)
-
13
SCF Assessor Certification Exam
-
(Included in full purchase)
SCF Assessor Knowledge Exam
-
(Included in full purchase)