Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
GRC - Governance, Risk & Compliance

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-GRC-05: Information Security Program

Operate an information security programme that covers all the domains of the control framework rather than a chosen subset.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 45 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APRA CPS 234 · 4 controls

  • CPS234-13 Board Responsibility for Information Security
  • CPS234-15 Information Security Capability
  • CPS234-19 Information Security Policy Framework
  • CPS234-21 Implementation of Information Security Controls

NIST SP 800-161 Rev 1 · 4 controls

  • CPS220-04 Maintenance of a Risk Management Framework
  • CPS220-07 Material Risk Categories the Framework Must Address
  • CPS220-P47 Minimum Assessment Required by the Framework Review

DORA · 3 controls

SOC 2 · 3 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • CPS230-24 Design and Embedding of Internal Controls
  • CPS230-P25 Information and Technology Capability and Asset Health
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • ASBv3-GS-5 Define and implement security posture management strategy
  • GS-1 Align organization roles, responsibilities and accountabilities

HIPAA Security Rule · 2 controls

NIS2 Directive · 2 controls

  • Art.21.1 Take proportionate all-hazards measures calibrated to the entity's own risk exposure
  • Art.21.2.a Policies on risk analysis and on information system security

NIST SP 800-53 Rev 5 · 2 controls

C5 (Germany) · 1 control

  • C5-OIS-01 Information Security Management System (ISMS)

CMMC 2.0 · 1 control

FedRAMP High · 1 control

  • PL-2 System Security and Privacy Plans

FedRAMP Moderate · 1 control

  • PL-2 System Security and Privacy Plans

ISO 27001:2022 · 1 control

  • 5.1 Policies for information security

ISO 27002:2022 · 1 control

  • 5.1 Policies for information security

ISO 27701:2019 · 1 control

  • 5.2.4 Information security management system
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

PCI DSS 4.0 · 1 control

  • 12.1.1 12.1.1 Overall information security policy established and disseminated

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GRC - Governance, Risk & Compliance

You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-GRC-05 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.