Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
IAM - Identity & Access Management

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-IAM-03: Identity Inventory

Hold a record of every system identity and the access level it carries, and review that record.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 36 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 3 controls

  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.5 Establish and Maintain an Inventory of Service Accounts
  • CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems

FedRAMP High · 3 controls

  • AC-2 Account Management
  • IA-4 Identifier Management
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))

FedRAMP Moderate · 3 controls

  • AC-2 Account Management
  • IA-4 Identifier Management
  • IA-4(4) Identifier Management | Identify User Status (IA-4(4))

PCI DSS 4.0 · 3 controls

  • 8.2.4 8.2.4 User ID lifecycle changes authorized
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 8.6.1 8.6.1 Interactive use of system accounts controlled
  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • SEC02-BP04 Rely on a centralized identity provider
  • SEC02-BP05 Audit and rotate credentials periodically
  • MYHR-REG-11 Ensuring required information is given to the System Operator
  • MYHR-SEC-2 Access controls and user account management
  • IM-1 Use centralized identity and authentication system
  • IM-3 Manage application identities securely and automatically

CMMC 2.0 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

C5 (Germany) · 1 control

  • C5-IDM-02 Granting and change of user accounts and access rights

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.16 Identity management

ISO 27002:2022 · 1 control

  • 5.16 Identity management

ISO 27701:2019 · 1 control

  • 6.6.2 User access management
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization

SOC 2 · 1 control

  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials

UK Cyber Essentials · 1 control

  • CE-AC.4 Privileged Account Approval and Tracking

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in IAM - Identity & Access Management

You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-IAM-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 36 it maps to, and the evidence behind each claim, over MCP and REST.