CCM-A&A-01 | Audit and Assurance Policy and Procedures | 25 |
CCM-A&A-02 | Independent Assessments | 36 |
CCM-A&A-03 | Risk Based Planning Assessment | 27 |
CCM-A&A-04 | Requirements Compliance | 31 |
CCM-A&A-05 | Audit Management Process | 28 |
CCM-A&A-06 | Remediation | 34 |
CCM-AIS-01 | Application and Interface Security Policy and Procedures | 18 |
CCM-AIS-02 | Application Security Baseline Requirements | 24 |
CCM-AIS-03 | Application Security Metrics | 11 |
CCM-AIS-04 | Secure Application Design and Development | 27 |
CCM-AIS-05 | Automated Application Security Testing | 22 |
CCM-AIS-06 | Automated Secure Application Deployment | 18 |
CCM-AIS-07 | Application Vulnerability Remediation | 26 |
CCM-BCR-01 | Business Continuity Management Policy and Procedures | 22 |
CCM-BCR-02 | Risk Assessment and Impact Analysis | 26 |
CCM-BCR-03 | Business Continuity Strategy | 22 |
CCM-BCR-04 | Business Continuity Planning | 25 |
CCM-BCR-05 | Documentation | 19 |
CCM-BCR-06 | Business Continuity Exercises | 25 |
CCM-BCR-07 | Communication | 21 |
CCM-BCR-08 | Backup | 28 |
CCM-BCR-09 | Disaster Response Plan | 25 |
CCM-BCR-10 | Response Plan Exercise | 22 |
CCM-BCR-11 | Equipment Redundancy | 16 |
CCM-CCC-01 | Change Management Policy and Procedures | 28 |
CCM-CCC-02 | Quality Testing | 22 |
CCM-CCC-03 | Change Management Technology | 18 |
CCM-CCC-04 | Unauthorized Change Protection | 28 |
CCM-CCC-05 | Change Agreements | 12 |
CCM-CCC-06 | Change Management Baseline | 25 |
CCM-CCC-07 | Detection of Baseline Deviation | 21 |
CCM-CCC-08 | Exception Management | 16 |
CCM-CCC-09 | Change Restoration | 17 |
CCM-CEK-01 | Encryption and Key Management Policy and Procedures | 21 |
CCM-CEK-02 | CEK Roles and Responsibilities | 14 |
CCM-CEK-03 | Data Encryption | 31 |
CCM-CEK-04 | Encryption Algorithm | 22 |
CCM-CEK-05 | Encryption Change Management | 10 |
CCM-CEK-06 | Encryption Change Cost Benefit Analysis | 0 |
CCM-CEK-07 | Encryption Risk Management | 8 |
CCM-CEK-08 | CSC Key Management Capability | 11 |
CCM-CEK-09 | Encryption and Key Management Audit | 13 |
CCM-CEK-10 | Key Generation | 17 |
CCM-CEK-11 | Key Purpose | 13 |
CCM-CEK-12 | Key Rotation | 16 |
CCM-CEK-13 | Key Revocation | 14 |
CCM-CEK-14 | Key Destruction | 13 |
CCM-CEK-15 | Key Activation | 10 |
CCM-CEK-16 | Key Suspension | 3 |
CCM-CEK-17 | Key Deactivation | 5 |
CCM-CEK-18 | Key Archival | 4 |
CCM-CEK-19 | Key Compromise | 12 |
CCM-CEK-20 | Key Recovery | 9 |
CCM-CEK-21 | Key Inventory Management | 14 |
CCM-DCS-01 | Off-Site Equipment Disposal Policy and Procedures | 21 |
CCM-DCS-02 | Off-Site Transfer Authorization Policy and Procedures | 17 |
CCM-DCS-03 | Secure Area Policy and Procedures | 21 |
CCM-DCS-04 | Secure Media Transportation Policy and Procedures | 19 |
CCM-DCS-05 | Assets Classification | 21 |
CCM-DCS-06 | Assets Cataloguing and Tracking | 26 |
CCM-DCS-07 | Controlled Access Points | 25 |
CCM-DCS-08 | Equipment Identification | 16 |
CCM-DCS-09 | Secure Area Authorization | 21 |
CCM-DCS-10 | Surveillance System | 18 |
CCM-DCS-11 | Unauthorized Access Response Training | 16 |
CCM-DCS-12 | Cabling Security | 14 |
CCM-DCS-13 | Environmental Systems | 13 |
CCM-DCS-14 | Secure Utilities | 14 |
CCM-DCS-15 | Equipment Location | 14 |
CCM-DSP-01 | Security and Privacy Policy and Procedures | 27 |
CCM-DSP-02 | Secure Disposal | 30 |
CCM-DSP-03 | Data Inventory | 26 |
CCM-DSP-04 | Data Classification | 26 |
CCM-DSP-05 | Data Flow Documentation | 25 |
CCM-DSP-06 | Data Ownership and Stewardship | 20 |
CCM-DSP-07 | Data Protection by Design and Default | 24 |
CCM-DSP-08 | Data Privacy by Design and Default | 16 |
CCM-DSP-09 | Data Protection Impact Assessment | 19 |
CCM-DSP-10 | Sensitive Data Transfer | 31 |
CCM-DSP-11 | Personal Data Access, Reversal, Rectification and Deletion | 14 |
CCM-DSP-12 | Limitation of Purpose in Personal Data Processing | 13 |
CCM-DSP-13 | Personal Data Sub-processing | 22 |
CCM-DSP-14 | Disclosure of Data Sub-processors | 20 |
CCM-DSP-15 | Limitation of Production Data Use | 12 |
CCM-DSP-16 | Data Retention and Deletion | 32 |
CCM-DSP-17 | Sensitive Data Protection | 30 |
CCM-DSP-18 | Disclosure Notification | 21 |
CCM-DSP-19 | Data Location | 21 |
CCM-GRC-01 | Governance Program Policy and Procedures | 35 |
CCM-GRC-02 | Risk Management Program | 34 |
CCM-GRC-03 | Organizational Policy Reviews | 29 |
CCM-GRC-04 | Policy Exception Process | 17 |
CCM-GRC-05 | Information Security Program | 29 |
CCM-GRC-06 | Governance Responsibility Model | 32 |
CCM-GRC-07 | Information System Regulatory Mapping | 27 |
CCM-GRC-08 | Special Interest Groups | 18 |
CCM-HRS-01 | Background Screening Policy and Procedures | 24 |
CCM-HRS-02 | Acceptable Use of Technology Policy and Procedures | 20 |
CCM-HRS-03 | Clean Desk Policy and Procedures | 11 |
CCM-HRS-04 | Remote and Home Working Policy and Procedures | 21 |
CCM-HRS-05 | Asset returns | 17 |
CCM-HRS-06 | Employment Termination | 22 |
CCM-HRS-07 | Employment Agreement Process | 15 |
CCM-HRS-08 | Employment Agreement Content | 17 |
CCM-HRS-09 | Personnel Roles and Responsibilities | 32 |
CCM-HRS-10 | Non-Disclosure Agreements | 13 |
CCM-HRS-11 | Security Awareness Training | 38 |
CCM-HRS-12 | Personal and Sensitive Data Awareness and Training | 32 |
CCM-HRS-13 | Compliance User Responsibility | 25 |
CCM-IAM-01 | Identity and Access Management Policy and Procedures | 24 |
CCM-IAM-02 | Strong Password Policy and Procedures | 24 |
CCM-IAM-03 | Identity Inventory | 24 |
CCM-IAM-04 | Separation of Duties | 20 |
CCM-IAM-05 | Least Privilege | 34 |
CCM-IAM-06 | User Access Provisioning | 26 |
CCM-IAM-07 | User Access Changes and Revocation | 26 |
CCM-IAM-08 | User Access Review | 25 |
CCM-IAM-09 | Segregation of Privileged Access Roles | 20 |
CCM-IAM-10 | Management of Privileged Access Roles | 25 |
CCM-IAM-11 | CSCs Approval for Agreed Privileged Access Roles | 11 |
CCM-IAM-12 | Safeguard Logs Integrity | 21 |
CCM-IAM-13 | Uniquely Identifiable Users | 28 |
CCM-IAM-14 | Strong Authentication | 31 |
CCM-IAM-15 | Passwords Management | 25 |
CCM-IAM-16 | Authorization Mechanisms | 25 |
CCM-IPY-01 | Interoperability and Portability Policy and Procedures | 11 |
CCM-IPY-02 | Application Interface Availability | 4 |
CCM-IPY-03 | Secure Interoperability and Portability Management | 19 |
CCM-IPY-04 | Data Portability Contractual Obligations | 16 |
CCM-IVS-01 | Infrastructure and Virtualization Security Policy and Procedures | 17 |
CCM-IVS-02 | Capacity and Resource Planning | 18 |
CCM-IVS-03 | Network Security | 31 |
CCM-IVS-04 | OS Hardening and Base Controls | 28 |
CCM-IVS-05 | Production and Non-Production Environments | 21 |
CCM-IVS-06 | Segmentation and Segregation | 24 |
CCM-IVS-07 | Migration to Cloud Environments | 17 |
CCM-IVS-08 | Network Architecture Documentation | 19 |
CCM-IVS-09 | Network Defense | 27 |
CCM-LOG-01 | Logging and Monitoring Policy and Procedures | 27 |
CCM-LOG-02 | Audit Logs Protection | 23 |
CCM-LOG-03 | Security Monitoring and Alerting | 31 |
CCM-LOG-04 | Audit Logs Access and Accountability | 20 |
CCM-LOG-05 | Audit Logs Monitoring and Response | 30 |
CCM-LOG-06 | Clock Synchronization | 19 |
CCM-LOG-07 | Logging Scope | 25 |
CCM-LOG-08 | Log Records | 24 |
CCM-LOG-09 | Log Protection | 19 |
CCM-LOG-10 | Encryption Monitoring and Reporting | 12 |
CCM-LOG-11 | Transaction/Activity Logging | 17 |
CCM-LOG-12 | Access Control Logs | 20 |
CCM-LOG-13 | Failures and Anomalies Reporting | 21 |
CCM-SEF-01 | Security Incident Management Policy and Procedures | 30 |
CCM-SEF-02 | Service Management Policy and Procedures | 17 |
CCM-SEF-03 | Incident Response Plans | 36 |
CCM-SEF-04 | Incident Response Testing | 27 |
CCM-SEF-05 | Incident Response Metrics | 20 |
CCM-SEF-06 | Event Triage Processes | 35 |
CCM-SEF-07 | Security Breach Notification | 31 |
CCM-SEF-08 | Points of Contact Maintenance | 31 |
CCM-STA-01 | SSRM Policy and Procedures | 20 |
CCM-STA-02 | SSRM Supply Chain | 20 |
CCM-STA-03 | SSRM Guidance | 17 |
CCM-STA-04 | SSRM Control Ownership | 20 |
CCM-STA-05 | SSRM Documentation Review | 17 |
CCM-STA-06 | SSRM Control Implementation | 15 |
CCM-STA-07 | Supply Chain Inventory | 28 |
CCM-STA-08 | Supply Chain Risk Management | 35 |
CCM-STA-09 | Primary Service and Contractual Agreement | 31 |
CCM-STA-10 | Supply Chain Agreement Review | 15 |
CCM-STA-11 | Internal Compliance Testing | 31 |
CCM-STA-12 | Supply Chain Service Agreement Compliance | 30 |
CCM-STA-13 | Supply Chain Governance Review | 21 |
CCM-STA-14 | Supply Chain Data Security Assessment | 30 |
CCM-TVM-01 | Threat and Vulnerability Management Policy and Procedures | 26 |
CCM-TVM-02 | Malware Protection Policy and Procedures | 26 |
CCM-TVM-03 | Vulnerability Remediation Schedule | 31 |
CCM-TVM-04 | Detection Updates | 26 |
CCM-TVM-05 | External Library Vulnerabilities | 25 |
CCM-TVM-06 | Penetration Testing | 24 |
CCM-TVM-07 | Vulnerability Identification | 31 |
CCM-TVM-08 | Vulnerability Prioritization | 25 |
CCM-TVM-09 | Vulnerability Management Reporting | 22 |
CCM-TVM-10 | Vulnerability Management Metrics | 7 |
CCM-UEM-01 | Endpoint Devices Policy and Procedures | 19 |
CCM-UEM-02 | Application and Service Approval | 26 |
CCM-UEM-03 | Compatibility | 7 |
CCM-UEM-04 | Endpoint Inventory | 23 |
CCM-UEM-05 | Endpoint Management | 25 |
CCM-UEM-06 | Automatic Lock Screen | 16 |
CCM-UEM-07 | Operating Systems | 22 |
CCM-UEM-08 | Storage Encryption | 21 |
CCM-UEM-09 | Anti-Malware Detection and Prevention | 25 |
CCM-UEM-10 | Software Firewall | 13 |
CCM-UEM-11 | Data Loss Prevention | 19 |
CCM-UEM-12 | Remote Locate | 2 |
CCM-UEM-13 | Remote Wipe | 6 |
CCM-UEM-14 | Third-Party Endpoint Security Posture | 20 |