Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
GRC - Governance, Risk & Compliance

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-GRC-06: Governance Responsibility Model

Document who plans, implements, operates, assesses and improves the governance programme, and what each of those roles is accountable for.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 53 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CPS220-09 Designation of a Chief Risk Officer
  • CPS220-10 Designated Risk Management Function
  • CPS220-P23 Minimum Contents of the Risk Management Framework
  • CPS220-P30 Minimum Contents of the Risk Management Strategy
  • CPS220-P36 Monitoring of Policy Review Dates and Ownership
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-05 Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
  • NIST-CSF-GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

NIST SP 800-181 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

PCI DSS 4.0 · 3 controls

  • 1.1.2 1.1.2 Requirement 1 roles and responsibilities assigned
  • 12.1.4 12.1.4 Executive ownership of information security formally assigned
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities

C5 (Germany) · 2 controls

  • C5-BCM-01 Top management responsibility
  • C5-OIS-01 Information Security Management System (ISMS)

FedRAMP High · 2 controls

  • CA-6 Authorization
  • PS-9 Position Descriptions (PS-9)

FedRAMP Moderate · 2 controls

  • CA-6 Authorization
  • PS-9 Position Descriptions (PS-9)

GDPR · 2 controls

ISO 22301:2019 · 2 controls

  • 5.1 Leadership and commitment
  • 5.3 Roles, responsibilities and authorities

ISO 27001:2022 · 2 controls

  • 5.2 Information security roles and responsibilities
  • 5.4 Management responsibilities

ISO 27002:2022 · 2 controls

  • 5.2 Information security roles and responsibilities
  • 5.4 Management responsibilities

NIST SP 800-161 Rev 1 · 2 controls

  • 161R1-PM-2 Information Security Program Leadership Role
  • 161R1-PM-29 Risk Management Program Leadership Roles

SOC 2 · 2 controls

  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • ANSSI-HYG-39 Designate an Information System Security Officer and Make the Role Known

APRA CPS 234 · 1 control

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • SEC11-BP08 Build a program that embeds security ownership in workload teams
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • GS-1 Align organization roles, responsibilities and accountabilities
  • CFTC-SS-2 Enterprise Risk Management and Governance Category
  • GRC-06 Governance Responsibility Model

DORA · 1 control

EU AI Act · 1 control

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • 5.3.3 Organizational roles, responsibilities and authorities

ISO/IEC 42001:2023 · 1 control

  • A.3.2 AI roles and responsibilities

NIS2 Directive · 1 control

  • Art.20.1 Management body approves the cybersecurity risk-management measures and oversees their implementation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GRC - Governance, Risk & Compliance

You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-GRC-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 53 it maps to, and the evidence behind each claim, over MCP and REST.