Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
A&A - Audit & Assurance

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-A&A-02: Independent Assessments

Commission audit and assurance assessments from assessors independent of the activity being examined, run them against recognised standards, and repeat them at least annually.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 56 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFTC-SS-15 Controls Testing
  • CFTC-SS-18 Independence of Testers
  • CFTC-SS-31 Testing Covers Outsourced Resources and Tester Independence from Providers
  • CFTC-SS-33 Regular Periodic Objective Testing and Review of Automated Systems
  • CFTC-SS-7 Generally Accepted Standards and Best Practices

APRA CPS 234 · 4 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P33 Skill of Personnel Providing Control Assurance

FedRAMP High · 4 controls

  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • CA-7(1) Independent Assessment

FedRAMP Moderate · 4 controls

  • CA-2 Control Assessments
  • CA-2(1) Independent Assessors
  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • CA-7(1) Independent Assessment
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness
  • STAR-L2-01 STAR Certification (ISO/IEC 27001 + CCM)
  • STAR-L2-02 STAR Attestation (SOC 2 + CCM)
  • STAR-L2-06 Surveillance and recertification cycle

NIST SP 800-172 · 3 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.12.1e Penetration Testing by Independent Agents
  • 3.14.7e Verify Correctness of Security Functions
  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-18 Triennial Comprehensive Review of the Framework

ISO 27701:2019 · 2 controls

  • 6.15.2 Information security reviews
  • 8.2.5 Customer obligations
  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

PCI DSS 4.0 · 2 controls

  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 11.4.3 11.4.3 External penetration testing annually and after change
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • CBPR-PR-34 Risk assessments and third party certifications
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program

C5 (Germany) · 1 control

  • C5-COM-03 Internal audits of the information security management system

CMMC 2.0 · 1 control

DORA · 1 control

EU AI Act · 1 control

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

ISO 27001:2022 · 1 control

  • 5.35 Independent review of information security

ISO 27002:2022 · 1 control

  • 5.35 Independent review of information security

ISO/IEC 42001:2023 · 1 control

  • 9.2.2 Internal audit programme

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

NIST SP 800-218 · 1 control

  • 53A-3.1 Prepare for Control Assessments

SOC 2 · 1 control

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in A&A - Audit & Assurance

You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-A&A-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 56 it maps to, and the evidence behind each claim, over MCP and REST.