Frameworks / Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 / CCM-IVS-06 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
IVS - Infrastructure & Virtualization Security
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-IVS-06: Segmentation and Segregation Segment and segregate provider and tenant access, and access between tenants, so one tenant cannot reach another, and monitor those boundaries.
Maintained by Gerard Blokdyk · Control text last updated 19 August 2026 What else in your programme already covers this This control maps to 63 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.3.1 1.3.1 Inbound CDE traffic restricted 1.3.3 1.3.3 NSCs between wireless networks and the CDE 1.4.1 1.4.1 NSCs between trusted and untrusted networks 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks 11.4.5 11.4.5 Annual segmentation penetration testing 11.4.6 11.4.6 Service provider segmentation testing every six months 2.2.3 2.2.3 Primary functions with different security levels managed C5-COS-03 Monitoring of connections in the Cloud Service Provider's network C5-COS-05 Networks for administration C5-COS-06 Segregation of data traffic in jointly used network environments C5-OPS-24 Separation of Datasets in the Cloud Infrastructure C5-PSS-10 Software Defined Networking AC-4 Information Flow Enforcement AC-4(21) Physical or Logical Separation of Information Flows SC-39 Process Isolation SC-4 Information in Shared System Resources SC-7 Boundary Protection AC-4 Information Flow Enforcement AC-4(21) Physical or Logical Separation of Information Flows SC-39 Process Isolation SC-4 Information in Shared System Resources SC-7 Boundary Protection ANSSI-HYG-19 Segment the Network and Partition the Zones ANSSI-HYG-20 Secure Wi-Fi Access Networks and Separate Usage ANSSI-HYG-23 Partition Internet Facing Services from the Rest of the Information System ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-13.4 Perform Traffic Filtering Between Network Segments CIS-3.12 Segment Data Processing and Storage Based on Sensitivity 3.1.3e Employ Secure Information Transfer Solutions 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation 3.13.4e Physical and Logical Isolation Techniques ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy NS-1 Establish network segmentation boundaries NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage ASD37-22 Network segmentation (Excellent) 8.22 Segregation of networks 8.22 Segregation of networks 6.10.1 Network security management SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in IVS - Infrastructure & Virtualization Security You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done? Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-IVS-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.