Back to Frameworks

CSA Cloud Controls Matrix v4

International
17 domains
197 controls

Cloud Security Alliance Cloud Controls Matrix v4. 197 controls across 17 cloud security domains.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (17)

Application & Interface Security

7 controls
Controls in the Application & Interface Security domain of CSA Cloud Controls Matrix v47 controls
CodeTitle
AIS-01Application and Interface Security Policy and Procedures
AIS-02Application Security Baseline Requirements
AIS-03Application Security Metrics
AIS-04Secure Application Design and Development
AIS-05Automated Application Security Testing
AIS-06Automated Secure Application Deployment
AIS-07Application Vulnerability Remediation

Audit & Assurance

6 controls
Controls in the Audit & Assurance domain of CSA Cloud Controls Matrix v46 controls
CodeTitle
AAS-01Audit and Assurance Policy and Procedures
AAS-02Independent Assessments
AAS-03Risk Based Planning Assessment
AAS-04Requirements Compliance
AAS-05Audit Management Process
AAS-06Remediation

Business Continuity

11 controls
Controls in the Business Continuity domain of CSA Cloud Controls Matrix v411 controls
CodeTitle
BCR-01Business Continuity Management Policy
BCR-02Risk Assessment and Impact Analysis
BCR-03Business Continuity Strategy
BCR-04Business Continuity Planning
BCR-05Documentation
BCR-06Business Continuity Exercises
BCR-07Communication
BCR-08Backup
BCR-09Disaster Response Testing
BCR-10Response Plan Exercise
BCR-11Equipment Redundancy

Change Control & Configuration Management

9 controls
Controls in the Change Control & Configuration Management domain of CSA Cloud Controls Matrix v49 controls
CodeTitle
CCC-01Change Management Policy
CCC-02Quality Testing
CCC-03Change Management Technology
CCC-04Unauthorized Change Protection
CCC-05Change Agreements
CCC-06Change Management Baseline
CCC-07Detection of Baseline Deviation
CCC-08Exception Management
CCC-09Change Restoration

Cryptography Encryption & Key Management

21 controls
Controls in the Cryptography Encryption & Key Management domain of CSA Cloud Controls Matrix v421 controls
CodeTitle
CEK-01Encryption and Key Management Policy
CEK-02CEK Roles and Responsibilities
CEK-03Data Encryption
CEK-04Encryption Algorithm
CEK-05Encryption Change Management
CEK-06Encryption Change Cost Benefit Analysis
CEK-07Encryption Risk Management
CEK-08CSC Key Management Capability
CEK-09Encryption and Key Management Audit
CEK-10Key Generation
CEK-11Key Rotation
CEK-12Key Rotation
CEK-13Key Revocation
CEK-14Key Destruction
CEK-15Key Activation
CEK-16Key Suspension
CEK-17Key Deactivation
CEK-18Key Archival
CEK-19Key Compromise
CEK-20Key Recovery
CEK-21Key Inventory Management

Data Security & Privacy

19 controls
Controls in the Data Security & Privacy domain of CSA Cloud Controls Matrix v419 controls
CodeTitle
DSP-01Disposal and End-of-Mission
DSP-02Data Inventory
DSP-03Data Inventory
DSP-04Data Classification
DSP-05Data Flow Documentation
DSP-06Data Ownership and Stewardship
DSP-07Data Protection by Design and Default
DSP-08Data Privacy by Design and Default
DSP-09Data Protection Impact Assessment
DSP-10Sensitive Data Transfer
DSP-11Personal Data Access Disclosure and Notification
DSP-12Limitation of Purpose in Personal Data Processing
DSP-13Personal Data Sub processing
DSP-14Disclosure of Data Sub processors
DSP-15Limitation of Production Data Use
DSP-16Data Retention and Deletion
DSP-17Sensitive Data Protection
DSP-18Disclosure Notification
DSP-19Data Location

Datacenter Security

15 controls
Controls in the Datacenter Security domain of CSA Cloud Controls Matrix v415 controls
CodeTitle
DCS-01Off-site Equipment Disposal
DCS-02Off Site Transfer Authorization Policy and Procedures
DCS-03Secure Area Policy and Procedures
DCS-04Secure Media Transportation Policy and Procedures
DCS-05Assets Classification
DCS-06Assets Cataloguing and Tracking
DCS-07Controlled Access Points
DCS-08Equipment Identification
DCS-09Secure Area Authorization
DCS-10Surveillance System
DCS-11Unauthorized Access Response Training
DCS-12Cabling Security
DCS-13Environmental Systems
DCS-14Secure Utilities
DCS-15Equipment Location

Governance Risk & Compliance

8 controls
Controls in the Governance Risk & Compliance domain of CSA Cloud Controls Matrix v48 controls
CodeTitle
GRC-01Governance Program
GRC-02Risk Management Program
GRC-03Organizational Policy Reviews
GRC-04Policy Exception Process
GRC-05Information Security Program
GRC-06Governance Responsibility Model
GRC-07Information System Regulatory Mapping
GRC-08Special Interest Groups

Human Resources

13 controls
Controls in the Human Resources domain of CSA Cloud Controls Matrix v413 controls
CodeTitle
HRS-01Background Screening
HRS-02Security Training
HRS-03Clean Desk Policy and Procedures
HRS-04Employment Termination
HRS-05Asset returns
HRS-06Employment Termination
HRS-07Employment Agreement Process
HRS-08Employment Agreement Content
HRS-09Personnel Roles and Responsibilities
HRS-10Non Disclosure Agreements
HRS-11Security Awareness Training
HRS-12Personal and Sensitive Data Awareness and Training
HRS-13Compliance User Responsibility

Identity & Access Management

16 controls
Controls in the Identity & Access Management domain of CSA Cloud Controls Matrix v416 controls
CodeTitle
IAM-01Identity and Access Management Policy
IAM-02Strong Authentication
IAM-03Identity Inventory
IAM-04Separation of Duties
IAM-05Least Privilege
IAM-06User Access Provisioning
IAM-07User Access Changes and Revocation
IAM-08User Access Review
IAM-09Segregation of Privileged Access Roles
IAM-10Management of Privileged Access Roles
IAM-11CSCs Approval for Agreed Privileged Access Roles
IAM-12Safeguard Logs Integrity
IAM-13Uniquely Identifiable Users
IAM-14Strong Authentication
IAM-15Passwords Management
IAM-16Authorization Mechanisms

Infrastructure & Virtualization Security

9 controls
Controls in the Infrastructure & Virtualization Security domain of CSA Cloud Controls Matrix v49 controls
CodeTitle
IVS-01Infrastructure and Virtualization Security
IVS-02Capacity and Resource Planning
IVS-03Network Security
IVS-04Network Security
IVS-05Production and Non Production Environments
IVS-06Segmentation and Segregation
IVS-07Migration to Cloud Environments
IVS-08Network Architecture Documentation
IVS-09Network Defense

Interoperability & Portability

4 controls
Controls in the Interoperability & Portability domain of CSA Cloud Controls Matrix v44 controls
CodeTitle
IPY-01Interoperability and Portability
IPY-02Interoperability and Portability Policies
IPY-03Secure Interoperability and Portability Management
IPY-04Data Portability Contractual Obligations

Logging and Monitoring

13 controls
Controls in the Logging and Monitoring domain of CSA Cloud Controls Matrix v413 controls
CodeTitle
LOG-01Logging and Monitoring
LOG-02Audit Logs Protection
LOG-03Security Monitoring and Alerting
LOG-04Audit Logs Access and Accountability
LOG-05Audit Logs Monitoring and Response
LOG-06Clock Synchronization
LOG-07Logging Scope
LOG-08Log Records
LOG-09Log Protection
LOG-10Encryption Monitoring and Reporting
LOG-11Transaction/Activity Logging
LOG-12Access Control Logs
LOG-13Failures and Anomalies

Security Incident Mgmt

8 controls
Controls in the Security Incident Mgmt domain of CSA Cloud Controls Matrix v48 controls
CodeTitle
SEF-01Security Incident Management Policy
SEF-02Service Management Policy and Procedures
SEF-03Incident Response Plans
SEF-04Incident Response Testing
SEF-05Incident Response Metrics
SEF-06Event Triage Processes
SEF-07Security Breach Notification
SEF-08Points of Contact Maintenance

Supply Chain Management

14 controls
Controls in the Supply Chain Management domain of CSA Cloud Controls Matrix v414 controls
CodeTitle
STA-01SSRM Policy and Procedures
STA-02SSRM Supply Chain
STA-03SSRM Guidance
STA-04SSRM Control Ownership
STA-05SSRM Documentation Review
STA-06Supply Chain Data Security
STA-07Supply Chain Inventory
STA-08Supply Chain Risk Management
STA-09Primary Service and Contractual Agreement
STA-10Supply Chain Agreement Review
STA-11Internal Compliance Testing
STA-12Supply Chain Service Agreement Compliance
STA-13Supply Chain Governance Review
STA-14Supply Chain Data Security Assessment

Threat & Vulnerability

10 controls
Controls in the Threat & Vulnerability domain of CSA Cloud Controls Matrix v410 controls
CodeTitle
TVM-01Threat and Vulnerability Management Policy
TVM-02Malware Protection Policy and Procedures
TVM-03Vulnerability Remediation Schedule
TVM-04Detection Updates
TVM-05External Library Vulnerabilities
TVM-06Penetration Testing
TVM-07Vulnerability Prioritization
TVM-08Vulnerability Prioritization
TVM-09Vulnerability Management Reporting
TVM-10Vulnerability Management Metrics

Universal Endpoint Management

14 controls
Controls in the Universal Endpoint Management domain of CSA Cloud Controls Matrix v414 controls
CodeTitle
UEM-01Endpoint Management
UEM-02Application and Service Approval
UEM-03Compatibility
UEM-04Endpoint Inventory
UEM-05Endpoint Management
UEM-06Automatic Lock Screen
UEM-07Operating Systems
UEM-08Storage Encryption
UEM-09Endpoint Management Software Firewall
UEM-10Software Firewall
UEM-11Data Loss Prevention
UEM-12Remote Locate
UEM-13Remote Wipe
UEM-14Third Party Endpoint Security Posture

Frequently Asked Questions

What is CSA Cloud Controls Matrix v4?

CSA Cloud Controls Matrix v4 is a compliance framework from International with 17 domains and 197 controls. Cloud Security Alliance Cloud Controls Matrix v4. 197 controls across 17 cloud security domains. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does CSA Cloud Controls Matrix v4 have?

CSA Cloud Controls Matrix v4 has 197 controls organised across 17 domains. The largest domains are Cryptography Encryption & Key Management (21 controls), Data Security & Privacy (19 controls), Identity & Access Management (16 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does CSA Cloud Controls Matrix v4 map to?

CSA Cloud Controls Matrix v4 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with CSA Cloud Controls Matrix v4 compliance?

Start your CSA Cloud Controls Matrix v4 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CSA Cloud Controls Matrix v4 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 197 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required