Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
TVM - Threat & Vulnerability Management

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-TVM-09: Vulnerability Management Reporting

Track, and report on, the work of finding and fixing vulnerabilities, including notification to the stakeholders who need to know.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 27 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 3 controls

  • CA-5 Plan of Action and Milestones
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2(2) Automated Flaw Remediation Status

FedRAMP Moderate · 3 controls

  • CA-5 Plan of Action and Milestones
  • RA-5 Vulnerability Monitoring and Scanning
  • SI-2(2) Automated Flaw Remediation Status

NIST SP 800-218 · 3 controls

  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated

NIST SP 800-171 Rev 3 · 2 controls

  • 03.11.02 Vulnerability Monitoring and Scanning
  • 03.12.02 Plan of Action and Milestones

APRA CPS 234 · 1 control

  • CPS234-28 Escalation of Unremediated Testing Deficiencies
  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations
  • AUCDR-IS-4 Formal vulnerability management program
  • PV-2 Audit and enforce secure configurations

C5 (Germany) · 1 control

  • C5-PSS-03 Online Register of Known Vulnerabilities
  • CFTC-SS-36 Internal Reporting and Review by Senior Management and the Board

CMMC 2.0 · 1 control

DORA · 1 control

EU AI Act · 1 control

  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

PCI DSS 4.0 · 1 control

  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in TVM - Threat & Vulnerability Management

You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-TVM-09 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 27 it maps to, and the evidence behind each claim, over MCP and REST.