ChaptersCircleEventsBlog

Download Publication

CCM and CAIQ FAQ
CCM and CAIQ FAQ

CCM and CAIQ FAQ

Release Date: 04/05/2023

Working Group: Cloud Controls Matrix

The Cloud Controls Matrix (CCM) is a framework of controls (policies and procedures) that are essential for cloud computing security. It is created and updated by CSA and aligned to CSA best practices. The controls in CCM cover all key aspects of cloud technology and can be used to assess and guide the security of any cloud implementation. CSA has arranged CCM’s controls in both spreadsheet and machine-readable versions of yes/no questions that are easy to read and use, known as the Consensus Assessment Initiative Questionnaire (CAIQ). 

Learn more about what CCM and CAIQ are, why they’re important, and how to use them.
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
Requirements for Bodies Providing STAR Certification
Requirements for Bodies Providing STAR Certific...
NIST CSF v2 Cloud Community Profile - Based on CCM v4
NIST CSF v2 Cloud Community Profile - Based on ...
Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2
Informative Reference Details for the Mapping o...
A New Era for Compliance: Introducing the Compliance Automation Revolution (CAR)
A New Era for Compliance: Introducing the Compliance Automation Rev...
Published: 04/29/2025
Implementing CCM: Enterprise Risk Management Controls
Implementing CCM: Enterprise Risk Management Controls
Published: 04/25/2025
Implementing CCM: Data Protection and Privacy Controls
Implementing CCM: Data Protection and Privacy Controls
Published: 04/22/2025
Navigating the FedRAMP Evolution: How CSA CCM Provides a Solid Foundation
Navigating the FedRAMP Evolution: How CSA CCM Provides a Solid Foun...
Published: 04/03/2025
Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training