ITIL 5, SCF and the Compliance Illusion

ITIL 5, SCF and the Compliance Illusion

In this episode of the ITSM Practice Podcast, Luigi Ferri challenges the illusion of security frameworks and compliance culture. Exploring the Secure Controls Framework (SCF), ISO, NIST and ITIL 5, he exposes governance immaturity, framework sprawl and risk misalignment. A sharp reflection on cybersecurity governance, enterprise risk management and why compliance without thinking weakens leadership.


In this episode, we answer to:

Is compliance replacing real risk-based security governance?

Why do organizations accumulate ISO, NIST and SCF instead of clarifying risk ownership?

How does ITIL 5 transform control frameworks into accountable governance?


Resources Mentioned in this Episode:

Compliance Forge website, article "The Secure Controls Framework (SCF) Is The Common Controls Framework (CCF)", link https://complianceforge.com/scf/what-is-the-scf/


Secure Controls Framework website, article "The SCF Makes Compliance A Natural Byproduct of Secure Practices", link https://securecontrolsframework.com/what-is-the-scf/


Secure Controls Framework on GitHub, article "The Secure Controls Framework (SCF) is a meta-framework (framework of frameworks) that maps to over 100 cybersecurity and privacy-related laws, regulations and industry frameworks", link https://github.com/securecontrolsframework/securecontrolsframework


Secure Controls Framework website, article "Security, Compliance & Resilience (SCR) Principles", link https://securecontrolsframework.com/domains-principles/


Secure Controls Framework website, article "Secure, Compliant & Resilient Capability Maturity Model (SCR-CMM)", link https://securecontrolsframework.com/free/capability-maturity-model/


Connect with me on:

LinkedIn: https://www.linkedin.com/in/theitsmpractice/

Website: http://www.theitsmpractice.com

And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.


Credits:

Sound engineering by Alan Southgate - http://alsouthgate.co.uk/


Graphics by Yulia Kolodyazhnaya

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(159)

MSPs: Your AI Contracts Are Obsolete

MSPs: Your AI Contracts Are Obsolete

AI is transforming Managed Service Providers (MSPs) from managing technology to managing AI behavior. This episode explains why traditional service design, governance, contracts, and risk models are n...

11 Elo 16min

DARE25: Why Defense Isn't Enough

DARE25: Why Defense Isn't Enough

Discover why traditional cybersecurity defense is no longer enough in the AI era. Luigi Ferri explores the DARE25 framework, dynamic risk management, governance, Purple Teaming, accountability, and ad...

4 Elo 9min

ISO 28000: Your Resilience, Their Budget

ISO 28000: Your Resilience, Their Budget

In this episode of the ITSM Practice Podcast, Luigi Ferri explores why supply chain resilience has become one of the biggest strategic challenges for Government Managed Service Providers (MSPs). Using...

28 Heinä 13min

No SBOM, No Trust

No SBOM, No Trust

Discover why the Software Bill of Materials (SBOM) is rapidly becoming a strategic necessity for Managed Service Providers (MSPs) and enterprise IT leaders. In this episode, Luigi Ferri explains how s...

21 Heinä 19min

PSD3: Who Owns Trust?

PSD3: Who Owns Trust?

PSD3 is more than a compliance requirement, it's a test of organisational maturity, security leadership, accountability, and decision-making. Discover how Enterprise Service Management, IT Service Man...

14 Heinä 6min

The Hidden Cost of Untrusted Data

The Hidden Cost of Untrusted Data

Why do organizations struggle to trust their operational data despite having plenty of it? In this episode of The ITSM Practice Podcast, Luigi Ferri explains the critical difference between data quali...

7 Heinä 11min

ITIL 5 Foundation: Exam Success

ITIL 5 Foundation: Exam Success

Preparing for the ITIL 5 Foundation exam? Discover why successful candidates focus on understanding the ITIL Value System, Value Chain, Governance, AI Capability, Four Dimensions, and Service Lifecycl...

30 Kesä 10min

PSD3: Governance Before Technology

PSD3: Governance Before Technology

In this episode, Luigi Ferri explores why organisations often take the wrong first step when preparing for PSD3 compliance. Rather than rushing into new tools, fraud platforms, or transformation progr...

23 Kesä 7min