Back to Frameworks

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1

International
v4.0.1
17 domains
197 controls

Cloud Security Alliance Cloud Controls Matrix - cybersecurity control framework for cloud computing

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (17)

A&A - Audit & Assurance

6 controls
Controls in the A&A - Audit & Assurance domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.16 controls
CodeTitle
CCM-A&A-01Audit and Assurance Policy and Procedures
CCM-A&A-02Independent Assessments
CCM-A&A-03Risk Based Planning Assessment
CCM-A&A-04Requirements Compliance
CCM-A&A-05Audit Management Process
CCM-A&A-06Remediation

AIS - Application & Interface Security

7 controls
Controls in the AIS - Application & Interface Security domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.17 controls
CodeTitle
CCM-AIS-01Application and Interface Security Policy and Procedures
CCM-AIS-02Application Security Baseline Requirements
CCM-AIS-03Application Security Metrics
CCM-AIS-04Secure Application Design and Development
CCM-AIS-05Automated Application Security Testing
CCM-AIS-06Automated Secure Application Deployment
CCM-AIS-07Application Vulnerability Remediation

BCR - Business Continuity Management & Operational Resilience

11 controls
Controls in the BCR - Business Continuity Management & Operational Resilience domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.111 controls
CodeTitle
CCM-BCR-01Business Continuity Management Policy and Procedures
CCM-BCR-02Risk Assessment and Impact Analysis
CCM-BCR-03Business Continuity Strategy
CCM-BCR-04Business Continuity Planning
CCM-BCR-05Documentation
CCM-BCR-06Business Continuity Exercises
CCM-BCR-07Communication
CCM-BCR-08Backup
CCM-BCR-09Disaster Response Plan
CCM-BCR-10Response Plan Exercise
CCM-BCR-11Equipment Redundancy

CCC - Change Control & Configuration Management

9 controls
Controls in the CCC - Change Control & Configuration Management domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.19 controls
CodeTitle
CCM-CCC-01Change Management Policy and Procedures
CCM-CCC-02Quality Testing
CCM-CCC-03Change Management Technology
CCM-CCC-04Unauthorized Change Protection
CCM-CCC-05Change Agreements
CCM-CCC-06Change Management Baseline
CCM-CCC-07Detection of Baseline Deviation
CCM-CCC-08Exception Management
CCM-CCC-09Change Restoration

CEK - Cryptography, Encryption & Key Management

21 controls
Controls in the CEK - Cryptography, Encryption & Key Management domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.121 controls
CodeTitle
CCM-CEK-01Encryption and Key Management Policy and Procedures
CCM-CEK-02CEK Roles and Responsibilities
CCM-CEK-03Data Encryption
CCM-CEK-04Encryption Algorithm
CCM-CEK-05Encryption Change Management
CCM-CEK-06Encryption Change Cost Benefit Analysis
CCM-CEK-07Encryption Risk Management
CCM-CEK-08CSC Key Management Capability
CCM-CEK-09Encryption and Key Management Audit
CCM-CEK-10Key Generation
CCM-CEK-11Key Purpose
CCM-CEK-12Key Rotation
CCM-CEK-13Key Revocation
CCM-CEK-14Key Destruction
CCM-CEK-15Key Activation
CCM-CEK-16Key Suspension
CCM-CEK-17Key Deactivation
CCM-CEK-18Key Archival
CCM-CEK-19Key Compromise
CCM-CEK-20Key Recovery
CCM-CEK-21Key Inventory Management

DCS - Datacenter Security

15 controls
Controls in the DCS - Datacenter Security domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.115 controls
CodeTitle
CCM-DCS-01Off-Site Equipment Disposal Policy and Procedures
CCM-DCS-02Off-Site Transfer Authorization Policy and Procedures
CCM-DCS-03Secure Area Policy and Procedures
CCM-DCS-04Secure Media Transportation Policy and Procedures
CCM-DCS-05Assets Classification
CCM-DCS-06Assets Cataloguing and Tracking
CCM-DCS-07Controlled Access Points
CCM-DCS-08Equipment Identification
CCM-DCS-09Secure Area Authorization
CCM-DCS-10Surveillance System
CCM-DCS-11Unauthorized Access Response Training
CCM-DCS-12Cabling Security
CCM-DCS-13Environmental Systems
CCM-DCS-14Secure Utilities
CCM-DCS-15Equipment Location

DSP - Data Security & Privacy Lifecycle Management

19 controls
Controls in the DSP - Data Security & Privacy Lifecycle Management domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.119 controls
CodeTitle
CCM-DSP-01Security and Privacy Policy and Procedures
CCM-DSP-02Secure Disposal
CCM-DSP-03Data Inventory
CCM-DSP-04Data Classification
CCM-DSP-05Data Flow Documentation
CCM-DSP-06Data Ownership and Stewardship
CCM-DSP-07Data Protection by Design and Default
CCM-DSP-08Data Privacy by Design and Default
CCM-DSP-09Data Protection Impact Assessment
CCM-DSP-10Sensitive Data Transfer
CCM-DSP-11Personal Data Access, Reversal, Rectification and Deletion
CCM-DSP-12Limitation of Purpose in Personal Data Processing
CCM-DSP-13Personal Data Sub-processing
CCM-DSP-14Disclosure of Data Sub-processors
CCM-DSP-15Limitation of Production Data Use
CCM-DSP-16Data Retention and Deletion
CCM-DSP-17Sensitive Data Protection
CCM-DSP-18Disclosure Notification
CCM-DSP-19Data Location

GRC - Governance, Risk & Compliance

8 controls
Controls in the GRC - Governance, Risk & Compliance domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.18 controls
CodeTitle
CCM-GRC-01Governance Program Policy and Procedures
CCM-GRC-02Risk Management Program
CCM-GRC-03Organizational Policy Reviews
CCM-GRC-04Policy Exception Process
CCM-GRC-05Information Security Program
CCM-GRC-06Governance Responsibility Model
CCM-GRC-07Information System Regulatory Mapping
CCM-GRC-08Special Interest Groups

HRS - Human Resources Security

13 controls
Controls in the HRS - Human Resources Security domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.113 controls
CodeTitle
CCM-HRS-01Background Screening Policy and Procedures
CCM-HRS-02Acceptable Use of Technology Policy and Procedures
CCM-HRS-03Clean Desk Policy and Procedures
CCM-HRS-04Remote and Home Working Policy and Procedures
CCM-HRS-05Asset returns
CCM-HRS-06Employment Termination
CCM-HRS-07Employment Agreement Process
CCM-HRS-08Employment Agreement Content
CCM-HRS-09Personnel Roles and Responsibilities
CCM-HRS-10Non-Disclosure Agreements
CCM-HRS-11Security Awareness Training
CCM-HRS-12Personal and Sensitive Data Awareness and Training
CCM-HRS-13Compliance User Responsibility

IAM - Identity & Access Management

16 controls
Controls in the IAM - Identity & Access Management domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.116 controls
CodeTitle
CCM-IAM-01Identity and Access Management Policy and Procedures
CCM-IAM-02Strong Password Policy and Procedures
CCM-IAM-03Identity Inventory
CCM-IAM-04Separation of Duties
CCM-IAM-05Least Privilege
CCM-IAM-06User Access Provisioning
CCM-IAM-07User Access Changes and Revocation
CCM-IAM-08User Access Review
CCM-IAM-09Segregation of Privileged Access Roles
CCM-IAM-10Management of Privileged Access Roles
CCM-IAM-11CSCs Approval for Agreed Privileged Access Roles
CCM-IAM-12Safeguard Logs Integrity
CCM-IAM-13Uniquely Identifiable Users
CCM-IAM-14Strong Authentication
CCM-IAM-15Passwords Management
CCM-IAM-16Authorization Mechanisms

IPY - Interoperability & Portability

4 controls
Controls in the IPY - Interoperability & Portability domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.14 controls
CodeTitle
CCM-IPY-01Interoperability and Portability Policy and Procedures
CCM-IPY-02Application Interface Availability
CCM-IPY-03Secure Interoperability and Portability Management
CCM-IPY-04Data Portability Contractual Obligations

IVS - Infrastructure & Virtualization Security

9 controls
Controls in the IVS - Infrastructure & Virtualization Security domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.19 controls
CodeTitle
CCM-IVS-01Infrastructure and Virtualization Security Policy and Procedures
CCM-IVS-02Capacity and Resource Planning
CCM-IVS-03Network Security
CCM-IVS-04OS Hardening and Base Controls
CCM-IVS-05Production and Non-Production Environments
CCM-IVS-06Segmentation and Segregation
CCM-IVS-07Migration to Cloud Environments
CCM-IVS-08Network Architecture Documentation
CCM-IVS-09Network Defense

LOG - Logging & Monitoring

13 controls
Controls in the LOG - Logging & Monitoring domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.113 controls
CodeTitle
CCM-LOG-01Logging and Monitoring Policy and Procedures
CCM-LOG-02Audit Logs Protection
CCM-LOG-03Security Monitoring and Alerting
CCM-LOG-04Audit Logs Access and Accountability
CCM-LOG-05Audit Logs Monitoring and Response
CCM-LOG-06Clock Synchronization
CCM-LOG-07Logging Scope
CCM-LOG-08Log Records
CCM-LOG-09Log Protection
CCM-LOG-10Encryption Monitoring and Reporting
CCM-LOG-11Transaction/Activity Logging
CCM-LOG-12Access Control Logs
CCM-LOG-13Failures and Anomalies Reporting

SEF - Security Incident Management, E-Discovery & Cloud Forensics

8 controls
Controls in the SEF - Security Incident Management, E-Discovery & Cloud Forensics domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.18 controls
CodeTitle
CCM-SEF-01Security Incident Management Policy and Procedures
CCM-SEF-02Service Management Policy and Procedures
CCM-SEF-03Incident Response Plans
CCM-SEF-04Incident Response Testing
CCM-SEF-05Incident Response Metrics
CCM-SEF-06Event Triage Processes
CCM-SEF-07Security Breach Notification
CCM-SEF-08Points of Contact Maintenance

STA - Supply Chain Management, Transparency & Accountability

14 controls
Controls in the STA - Supply Chain Management, Transparency & Accountability domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.114 controls
CodeTitle
CCM-STA-01SSRM Policy and Procedures
CCM-STA-02SSRM Supply Chain
CCM-STA-03SSRM Guidance
CCM-STA-04SSRM Control Ownership
CCM-STA-05SSRM Documentation Review
CCM-STA-06SSRM Control Implementation
CCM-STA-07Supply Chain Inventory
CCM-STA-08Supply Chain Risk Management
CCM-STA-09Primary Service and Contractual Agreement
CCM-STA-10Supply Chain Agreement Review
CCM-STA-11Internal Compliance Testing
CCM-STA-12Supply Chain Service Agreement Compliance
CCM-STA-13Supply Chain Governance Review
CCM-STA-14Supply Chain Data Security Assessment

TVM - Threat & Vulnerability Management

10 controls
Controls in the TVM - Threat & Vulnerability Management domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.110 controls
CodeTitle
CCM-TVM-01Threat and Vulnerability Management Policy and Procedures
CCM-TVM-02Malware Protection Policy and Procedures
CCM-TVM-03Vulnerability Remediation Schedule
CCM-TVM-04Detection Updates
CCM-TVM-05External Library Vulnerabilities
CCM-TVM-06Penetration Testing
CCM-TVM-07Vulnerability Identification
CCM-TVM-08Vulnerability Prioritization
CCM-TVM-09Vulnerability Management Reporting
CCM-TVM-10Vulnerability Management Metrics

UEM - Universal Endpoint Management

14 controls
Controls in the UEM - Universal Endpoint Management domain of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.114 controls
CodeTitle
CCM-UEM-01Endpoint Devices Policy and Procedures
CCM-UEM-02Application and Service Approval
CCM-UEM-03Compatibility
CCM-UEM-04Endpoint Inventory
CCM-UEM-05Endpoint Management
CCM-UEM-06Automatic Lock Screen
CCM-UEM-07Operating Systems
CCM-UEM-08Storage Encryption
CCM-UEM-09Anti-Malware Detection and Prevention
CCM-UEM-10Software Firewall
CCM-UEM-11Data Loss Prevention
CCM-UEM-12Remote Locate
CCM-UEM-13Remote Wipe
CCM-UEM-14Third-Party Endpoint Security Posture

Your Compliance Coverage

If you comply with Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, you already cover:

Maps to 19 other frameworks

197 total controls
NIST SP 800-53 Rev 5
33 source controls mapped|30 target controls covered
17%
CNCF Security Technical Advisory Group (TAG)
21 source controls mapped|24 target controls covered
11%
ISO 27018:2019
12 source controls mapped|10 target controls covered
6%
ISO 27002:2022
9 source controls mapped|7 target controls covered
5%
SOC 2
7 source controls mapped|7 target controls covered
4%
CSA STAR (Security, Trust, Assurance, and Risk)
4 source controls mapped|11 target controls covered
2%
ISO 27701:2019
4 source controls mapped|5 target controls covered
2%
Commercial National Security Algorithm Suite (CNSA) 2.0
4 source controls mapped|4 target controls covered
2%
ISO 31000:2018
3 source controls mapped|3 target controls covered
2%
ISO 13485:2016
2 source controls mapped|2 target controls covered
1%
ISO 27017:2015
2 source controls mapped|2 target controls covered
1%
ISO/IEC 42001:2023
2 source controls mapped|2 target controls covered
1%
ISO/IEC 23894:2023
2 source controls mapped|4 target controls covered
1%
ISO 10005:2005
1 source controls mapped|1 target controls covered
1%
ISO 19011
1 source controls mapped|1 target controls covered
1%
1%
ISO 27005:2022
1 source controls mapped|1 target controls covered
1%
ISO 10006:2003
1 source controls mapped|1 target controls covered
1%
ISO 22301:2019
1 source controls mapped|3 target controls covered
1%

Frequently Asked Questions

What is Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 is a compliance framework from International with 17 domains and 197 controls. Cloud Security Alliance Cloud Controls Matrix - cybersecurity control framework for cloud computing It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 has 197 controls organised across 17 domains. The largest domains are CEK - Cryptography, Encryption & Key Management (21 controls), DSP - Data Security & Privacy Lifecycle Management (19 controls), IAM - Identity & Access Management (16 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 map to?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 maps to 19 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (17% coverage), CNCF Security Technical Advisory Group (TAG) (11% coverage), ISO 27018:2019 (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 compliance?

Start your Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 197 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required