ITIL 5, SCF and the Compliance Illusion
Beyond the SDLC: Managing Continuous Change in Living Systems
ITIL 5, SCF and the Compliance Illusion

Summary
In this episode of **The ITSM Practice Podcast*, [Luigi Ferri](https://www.linkedin.com/in/theitsmpractice/)* explores the Secure Controls Framework (SCF) and why its value extends far beyond compliance.
By aligning multiple regulations and standards within a single control structure, SCF exposes governance inconsistencies, unclear risk ownership, and the decisions that shape organizational behavior.
Through the lens of ITIL 5, this episode examines why effective governance is not about passing audits, but about accountability, leadership, and understanding risk.
Are we using frameworks to understand risk, or to avoid difficult conversations about it?
If two regulations require essentially the same control, why do organizations often treat them so differently?
What would change in your organization if governance was viewed as a leadership responsibility rather than a compliance activity?
Listen to the Episode
🎧 Spotify: https://open.spotify.com/episode/2Uk8cxiT4hnG1pWyeMdoLb?si=AMqFzqYBReaQgNjSxRYpDQ
🎧 Apple Podcasts: https://podcasts.apple.com/us/podcast/itil-5-scf-and-the-compliance-illusion/id1720010566?i=1000754415274
Episode Transcript
Welcome to the third series of the ITSM Practice Podcast.
I am Luigi Ferri
Let me start with a statement that will make some of you uncomfortable.
Compliance is what organizations do when they don’t want to think.
They want certainty without judgment. Safety without responsibility. Assurance without leadership.
And over time, they collect frameworks the way nervous institutions collect insurance policies.
Not from clarity about risk… but from discomfort with uncertainty.
So how did security governance become an exercise in accumulation instead of reasoning?
What the Secure Controls Framework actually is
Before we go any further, let me be very clear about what we are talking about.
The Secure Controls Framework, or SCF, is a framework-of-frameworks.
It does not replace ISO, NIST, CMMC, FedRAMP, or any other standard. It normalizes them.
It takes more than a thousand security and privacy controls and aligns them across laws, regulations, and standards… using a single control language.
In practical terms:
- one control
- many obligations
- one place where inconsistency becomes visible
SCF is not elegant. It is not simple. And it is not inspirational.
It exists because regulated environments are fragmented, overlapping, and unforgiving.
And that is precisely why SCF is so revealing.
So what happens when all your frameworks are forced to speak the same language?
Topic 1 — The myth of the “right framework”
Most conversations about security frameworks still start with the wrong question:
Which framework should we adopt?
ISO. NIST. CMMC. FedRAMP. Something else.
This question assumes that framework choice is a technical decision.
It is not.
It is a governance decision pretending to be technical.
Framework sprawl does not happen because regulations are complex. It happens because leadership avoids making explicit trade-offs.
And frameworks quietly accept that role.
So what happens when frameworks multiply faster than understanding?
Topic 2 — Complexity is the tax of digital ambition
Here is the reality few executives like to face:
Complexity is the tax of digital ambition.
If you operate digital platforms, cloud services, regulated environments, and extended supply chains, complexity is not an accident.
It is the price of scale.
The problem is not complexity. The problem is pretending it can be neutralized with checklists.
Frameworks promise order. But order without interpretation is just bureaucracy with better branding.
So what do organizations really want from frameworks?
Topic 3 — Frameworks as a substitute for thinking
Most organizations don’t use frameworks to reason.
They use them to:
- defer accountability
- outsource judgment
- justify decisions already made
This is why compliance language is so attractive.
It removes verbs from leadership.
No one decides. Controls require. Standards mandate. Auditors expect.
And slowly, governance becomes something that happens to the organization… not by it.
So, where does SCF truly enter this picture?
Topic 4 — SCF as a necessary evil
Let’s be precise.
The Secure Controls Framework is not inspirational. It is not elegant. It is not simple.
It is a necessary evil in regulated markets.
A framework designed not to reduce obligations, but to expose how fragmented and redundant they really are.
SCF does something most frameworks avoid: it forces your governance assumptions into the open.
When one control covers ten different regulations, a harder question appears:
If the control is the same, why were we thinking differently before?
So what does SCF actually expose?
Topic 5 — SCF exposes governance immaturity
SCF does not reduce complexity. It reveals it.
It shows you:
- how often the same risk is managed inconsistently
- how many controls exist only because frameworks disagree
- how little of your security posture is actually intentional
This is why SCF separates operators from leaders.
Operators ask: How do we map this?
Leaders ask: Why does this control exist at all — and what risk does it truly govern?
SCF does not reward operational fluency. It rewards conceptual clarity.
And this is where ITIL 5 becomes unavoidable.
Topic 6 — Why ITIL 5 belongs at the center
ITIL 5 makes an implicit demand explicit:
Governance is not an overlay. It is part of how systems are designed.
When SCF is treated as a control library without ITIL 5 thinking, it becomes another compliance warehouse.
But when SCF is read through ITIL 5:
- controls become expressions of decisions
- lifecycle ownership becomes unavoidable
- accountability can no longer hide behind “the process”
This is not security management. This is institutional self-awareness.
So what choice does this force on MSP executives?
Closing — The brutal question
Managed Service Providers now stand at a crossroads.
You can continue to:
- collect frameworks
- satisfy audits
- demonstrate compliance
- and never articulate your risk logic
Or you can accept something harder:
That governance requires thinking. That frameworks are tools, not substitutes. That complexity demands leadership, not accumulation.
SCF will not save you. ITIL 5 will not save you.
They will only do one thing.
They will make it impossible to pretend you understand risk when you don’t.
So here is the only question that matters:
Are you using frameworks to protect your organization… or to protect yourself from having to think?
— -
Thank you for listening.
And this was **The ITSM Practice Podcast**.
I’m ***Luigi Ferri***.
Arrivederci.
— -
If you enjoyed this episode, follow **The ITSM Practice Podcast **for more conversations on:
- IT Service Management
- Enterprise Service Management
- AI Governance
- IT Security
- Digital Leadership
Thank you for listening. — ***Luigi Ferri***
메타데이터
- post_id
- fae7efaf996d
- slug
- itil-5-scf-and-the-compliance-illusion-fae7efaf996d
- url
- https://medium.com/the-itsm-practice-podcast/itil-5-scf-and-the-compliance-illusion-fae7efaf996d
- canonical_url
- https://medium.com/the-itsm-practice-podcast/itil-5-scf-and-the-compliance-illusion-fae7efaf996d
- author_url
- https://medium.com/@the_itsm_practice_podcast
- status
- ok
- fetched_at
- 2026-06-15 20:49:13