SCF
Secure Controls Framework — a meta-framework with ~1,200 controls that map to 79+ regulatory standards.
ERL
Evidence Requirement List — the evidence expected for a control.
Evidence Atom
A single extracted assertion from your document that supports or contradicts a control.
Mapping
A link between an SCF control and an external framework's control.
Coverage
The rolled-up support level (weak/moderate/strong) for a control given the atoms mapped to it.
Maturity
A 1–5 scale (Performed informally → Continuously improving) scoring how well the objective is implemented.
SCF Assessment Objective
Definition: A testable statement used to verify whether a control is actually satisfied.
In Graphletter: Graphletter evaluates each objective separately and then rolls those results into a control-level status.
Where you see it: Assessment Results and assessment review dialogs
Assessment Procedure
Definition: The expected method for checking whether an objective is met.
In Graphletter: Used as structured guidance for how evidence should be interpreted during objective evaluation.
Where you see it: Assessment objective data in API and detailed records
Expected Results
Definition: The condition or outcome that should be observable when a control is implemented correctly.
In Graphletter: Compared against evidence claims to determine objective-level pass, partial, or fail outcomes.
Where you see it: Assessment objective records and outputs
Pass / Partial / Fail / Not Applicable
Definition: Standard assessment outcomes describing whether evidence meets an objective.
In Graphletter: Objective-level outcomes that roll up into control-level status and dashboard metrics.
Where you see it: Assessment Results, control cards, reports
Confidence Score
Definition: An estimate of how strongly the current evidence supports an assessment result.
In Graphletter: Used to flag weaker conclusions even when a control appears to pass.
Where you see it: Assessment output, analytics, report exports