International

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1

197 controls. 59 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

197 controls 59 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CCM-A&A-01Audit and Assurance Policy and Procedures25
CCM-A&A-02Independent Assessments36
CCM-A&A-03Risk Based Planning Assessment27
CCM-A&A-04Requirements Compliance31
CCM-A&A-05Audit Management Process28
CCM-A&A-06Remediation34
CCM-AIS-01Application and Interface Security Policy and Procedures18
CCM-AIS-02Application Security Baseline Requirements24
CCM-AIS-03Application Security Metrics11
CCM-AIS-04Secure Application Design and Development27
CCM-AIS-05Automated Application Security Testing22
CCM-AIS-06Automated Secure Application Deployment18
CCM-AIS-07Application Vulnerability Remediation26
CCM-BCR-01Business Continuity Management Policy and Procedures22
CCM-BCR-02Risk Assessment and Impact Analysis26
CCM-BCR-03Business Continuity Strategy22
CCM-BCR-04Business Continuity Planning25
CCM-BCR-05Documentation19
CCM-BCR-06Business Continuity Exercises25
CCM-BCR-07Communication21
CCM-BCR-08Backup28
CCM-BCR-09Disaster Response Plan25
CCM-BCR-10Response Plan Exercise22
CCM-BCR-11Equipment Redundancy16
CCM-CCC-01Change Management Policy and Procedures28
CCM-CCC-02Quality Testing22
CCM-CCC-03Change Management Technology18
CCM-CCC-04Unauthorized Change Protection28
CCM-CCC-05Change Agreements12
CCM-CCC-06Change Management Baseline25
CCM-CCC-07Detection of Baseline Deviation21
CCM-CCC-08Exception Management16
CCM-CCC-09Change Restoration17
CCM-CEK-01Encryption and Key Management Policy and Procedures21
CCM-CEK-02CEK Roles and Responsibilities14
CCM-CEK-03Data Encryption31
CCM-CEK-04Encryption Algorithm22
CCM-CEK-05Encryption Change Management10
CCM-CEK-06Encryption Change Cost Benefit Analysis0
CCM-CEK-07Encryption Risk Management8
CCM-CEK-08CSC Key Management Capability11
CCM-CEK-09Encryption and Key Management Audit13
CCM-CEK-10Key Generation17
CCM-CEK-11Key Purpose13
CCM-CEK-12Key Rotation16
CCM-CEK-13Key Revocation14
CCM-CEK-14Key Destruction13
CCM-CEK-15Key Activation10
CCM-CEK-16Key Suspension3
CCM-CEK-17Key Deactivation5
CCM-CEK-18Key Archival4
CCM-CEK-19Key Compromise12
CCM-CEK-20Key Recovery9
CCM-CEK-21Key Inventory Management14
CCM-DCS-01Off-Site Equipment Disposal Policy and Procedures21
CCM-DCS-02Off-Site Transfer Authorization Policy and Procedures17
CCM-DCS-03Secure Area Policy and Procedures21
CCM-DCS-04Secure Media Transportation Policy and Procedures19
CCM-DCS-05Assets Classification21
CCM-DCS-06Assets Cataloguing and Tracking26
CCM-DCS-07Controlled Access Points25
CCM-DCS-08Equipment Identification16
CCM-DCS-09Secure Area Authorization21
CCM-DCS-10Surveillance System18
CCM-DCS-11Unauthorized Access Response Training16
CCM-DCS-12Cabling Security14
CCM-DCS-13Environmental Systems13
CCM-DCS-14Secure Utilities14
CCM-DCS-15Equipment Location14
CCM-DSP-01Security and Privacy Policy and Procedures27
CCM-DSP-02Secure Disposal30
CCM-DSP-03Data Inventory26
CCM-DSP-04Data Classification26
CCM-DSP-05Data Flow Documentation25
CCM-DSP-06Data Ownership and Stewardship20
CCM-DSP-07Data Protection by Design and Default24
CCM-DSP-08Data Privacy by Design and Default16
CCM-DSP-09Data Protection Impact Assessment19
CCM-DSP-10Sensitive Data Transfer31
CCM-DSP-11Personal Data Access, Reversal, Rectification and Deletion14
CCM-DSP-12Limitation of Purpose in Personal Data Processing13
CCM-DSP-13Personal Data Sub-processing22
CCM-DSP-14Disclosure of Data Sub-processors20
CCM-DSP-15Limitation of Production Data Use12
CCM-DSP-16Data Retention and Deletion32
CCM-DSP-17Sensitive Data Protection30
CCM-DSP-18Disclosure Notification21
CCM-DSP-19Data Location21
CCM-GRC-01Governance Program Policy and Procedures35
CCM-GRC-02Risk Management Program34
CCM-GRC-03Organizational Policy Reviews29
CCM-GRC-04Policy Exception Process17
CCM-GRC-05Information Security Program29
CCM-GRC-06Governance Responsibility Model32
CCM-GRC-07Information System Regulatory Mapping27
CCM-GRC-08Special Interest Groups18
CCM-HRS-01Background Screening Policy and Procedures24
CCM-HRS-02Acceptable Use of Technology Policy and Procedures20
CCM-HRS-03Clean Desk Policy and Procedures11
CCM-HRS-04Remote and Home Working Policy and Procedures21
CCM-HRS-05Asset returns17
CCM-HRS-06Employment Termination22
CCM-HRS-07Employment Agreement Process15
CCM-HRS-08Employment Agreement Content17
CCM-HRS-09Personnel Roles and Responsibilities32
CCM-HRS-10Non-Disclosure Agreements13
CCM-HRS-11Security Awareness Training38
CCM-HRS-12Personal and Sensitive Data Awareness and Training32
CCM-HRS-13Compliance User Responsibility25
CCM-IAM-01Identity and Access Management Policy and Procedures24
CCM-IAM-02Strong Password Policy and Procedures24
CCM-IAM-03Identity Inventory24
CCM-IAM-04Separation of Duties20
CCM-IAM-05Least Privilege34
CCM-IAM-06User Access Provisioning26
CCM-IAM-07User Access Changes and Revocation26
CCM-IAM-08User Access Review25
CCM-IAM-09Segregation of Privileged Access Roles20
CCM-IAM-10Management of Privileged Access Roles25
CCM-IAM-11CSCs Approval for Agreed Privileged Access Roles11
CCM-IAM-12Safeguard Logs Integrity21
CCM-IAM-13Uniquely Identifiable Users28
CCM-IAM-14Strong Authentication31
CCM-IAM-15Passwords Management25
CCM-IAM-16Authorization Mechanisms25
CCM-IPY-01Interoperability and Portability Policy and Procedures11
CCM-IPY-02Application Interface Availability4
CCM-IPY-03Secure Interoperability and Portability Management19
CCM-IPY-04Data Portability Contractual Obligations16
CCM-IVS-01Infrastructure and Virtualization Security Policy and Procedures17
CCM-IVS-02Capacity and Resource Planning18
CCM-IVS-03Network Security31
CCM-IVS-04OS Hardening and Base Controls28
CCM-IVS-05Production and Non-Production Environments21
CCM-IVS-06Segmentation and Segregation24
CCM-IVS-07Migration to Cloud Environments17
CCM-IVS-08Network Architecture Documentation19
CCM-IVS-09Network Defense27
CCM-LOG-01Logging and Monitoring Policy and Procedures27
CCM-LOG-02Audit Logs Protection23
CCM-LOG-03Security Monitoring and Alerting31
CCM-LOG-04Audit Logs Access and Accountability20
CCM-LOG-05Audit Logs Monitoring and Response30
CCM-LOG-06Clock Synchronization19
CCM-LOG-07Logging Scope25
CCM-LOG-08Log Records24
CCM-LOG-09Log Protection19
CCM-LOG-10Encryption Monitoring and Reporting12
CCM-LOG-11Transaction/Activity Logging17
CCM-LOG-12Access Control Logs20
CCM-LOG-13Failures and Anomalies Reporting21
CCM-SEF-01Security Incident Management Policy and Procedures30
CCM-SEF-02Service Management Policy and Procedures17
CCM-SEF-03Incident Response Plans36
CCM-SEF-04Incident Response Testing27
CCM-SEF-05Incident Response Metrics20
CCM-SEF-06Event Triage Processes35
CCM-SEF-07Security Breach Notification31
CCM-SEF-08Points of Contact Maintenance31
CCM-STA-01SSRM Policy and Procedures20
CCM-STA-02SSRM Supply Chain20
CCM-STA-03SSRM Guidance17
CCM-STA-04SSRM Control Ownership20
CCM-STA-05SSRM Documentation Review17
CCM-STA-06SSRM Control Implementation15
CCM-STA-07Supply Chain Inventory28
CCM-STA-08Supply Chain Risk Management35
CCM-STA-09Primary Service and Contractual Agreement31
CCM-STA-10Supply Chain Agreement Review15
CCM-STA-11Internal Compliance Testing31
CCM-STA-12Supply Chain Service Agreement Compliance30
CCM-STA-13Supply Chain Governance Review21
CCM-STA-14Supply Chain Data Security Assessment30
CCM-TVM-01Threat and Vulnerability Management Policy and Procedures26
CCM-TVM-02Malware Protection Policy and Procedures26
CCM-TVM-03Vulnerability Remediation Schedule31
CCM-TVM-04Detection Updates26
CCM-TVM-05External Library Vulnerabilities25
CCM-TVM-06Penetration Testing24
CCM-TVM-07Vulnerability Identification31
CCM-TVM-08Vulnerability Prioritization25
CCM-TVM-09Vulnerability Management Reporting22
CCM-TVM-10Vulnerability Management Metrics7
CCM-UEM-01Endpoint Devices Policy and Procedures19
CCM-UEM-02Application and Service Approval26
CCM-UEM-03Compatibility7
CCM-UEM-04Endpoint Inventory23
CCM-UEM-05Endpoint Management25
CCM-UEM-06Automatic Lock Screen16
CCM-UEM-07Operating Systems22
CCM-UEM-08Storage Encryption21
CCM-UEM-09Anti-Malware Detection and Prevention25
CCM-UEM-10Software Firewall13
CCM-UEM-11Data Loss Prevention19
CCM-UEM-12Remote Locate2
CCM-UEM-13Remote Wipe6
CCM-UEM-14Third-Party Endpoint Security Posture20

Tell me when Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • OT asset inventory
  • Zone and conduit diagram
  • Patch register
  • Remote access policy
  • Infrastructure/virtualization security policy
  • Network segmentation + defense architecture
  • network diagram
  • encryption inventory
  • key management procedure
  • secure config standards

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition