You're Not Getting Assurance With SOC 2. You're Getting Marketing Material | Guest: Tom Cornelius

You're Not Getting Assurance With SOC 2. You're Getting Marketing Material | Guest: Tom Cornelius

Source: YouTube · GRC Engineering Club · published Aug 2, 2026 · 59:10

Compliance & GRC
No ratings yet Log in to rate
Transcript Available
Description

The Secure Controls Framework (SCF) is a free, community-driven meta-framework helping organizations unify disparate compliance requirements and mitigate increasing personal liability risks for executives 1:26.

Key Takeaways:
• SCF adoption accelerates as organizations struggle with the inefficiencies of managing multiple overlapping frameworks like PCI, CMMC, and HIPAA in silos 1:18.
• CISOs face personal liability under laws like CCPA and NYDFS, making third-party validation and documented due diligence critical for legal defense 4:10.
• The framework is expanding to include post-quantum cryptography and zero-trust architectures to proactively address the "Harvest Now, Decrypt Later" (HONDO) threat 4:55.
• Data governance is fundamentally a business problem; organizations must define data longevity and value before applying technical security controls 8:15.
• SCF provides unified scoping guides and maturity models to help prioritize controls objectively, moving beyond simple checklists to assess compliance rigor 33:43.

Ultimately, the SCF aims to standardize security practices across industries to improve societal resilience while providing a defensible baseline for legal and insurance purposes 26:00.

Sources:

  • 1:26 Discussion on the inefficiencies of managing multiple compliance frameworks in silos.
  • 4:10 Explanation of personal liability for CISOs under California and New York regulations.
  • 4:55 Overview of the new quantum

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome friends to another edition of the Anti-Checkbox podcast. I am joined with someone who I've looked up to in this industry for quite a bit. So, your dreams can come true, kids. Sometimes you just got to link up with a club and start a podcast. Welcome Mr. Tom Cornelius. Tom, tell the people who for some reason don't know who you are tell them who you are what you what you're about. >> Sure. Thanks again for having me. I'm Tom Cornelius. The founder of the Secure Controls Framework, also senior partner at Compliance Forge. So, if you're not familiar with the SCF, we're we give away security control security controls for free. I've been doing it since 2018 and actually it's really kind of cool. We've we've got We're taking a look at stuff about 15% of the Fortune 2000 are now using the…