Cloud 101CircleEventsBlog
Register for CSA’s free Virtual Cloud Trust Summit to tackle enterprise challenges in cloud assurance.

Download Publication

CCM v3.0.1 Addendum - FedRAMP Moderate
CCM v3.0.1 Addendum - FedRAMP Moderate

CCM v3.0.1 Addendum - FedRAMP Moderate

Release Date: 08/03/2019

Working Group: Cloud Controls Matrix

This document is an addendum to the CCM V3.0.1 that contain controls mapping between the CSA CCM and the FedRAMP R4 Moderate Baseline.

The document aims to help FedRAMP compliant organizations meet CCM requirements. This is achieved by identifying compliance gaps in FedRAMP in
relation to the CCM. This document contains the following information:
• Controls Mapping
• Gap Analysis
• Gap Identification (i.e. Partial, Full or No Gap)
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
CCM v4.0 Addendum - ECUC PP v2.1
CCM v4.0 Addendum - ECUC PP v2.1
CSA CCM v4.0 Addendum - IBM Cloud Framework for Financial Services v1.1.0
CSA CCM v4.0 Addendum - IBM Cloud Framework for...
CSA CCM v4.0 Addendum - CRI FS Profile v1.2
CSA CCM v4.0 Addendum - CRI FS Profile v1.2
CSA Community Spotlight: Establishing Cloud Security Standards with Dr. Ricci Ieong
CSA Community Spotlight: Establishing Cloud Security Standards with...
Published: 04/03/2024
CSA Community Spotlight: Propelling the Industry Forward with Larry Whiteside Jr.
CSA Community Spotlight: Propelling the Industry Forward with Larry...
Published: 03/12/2024
A New Era of Data Protection: CSA’s Strategic Partnership with the EU Cloud CoC for GDPR Compliance
A New Era of Data Protection: CSA’s Strategic Partnership with the ...
Published: 02/29/2024
The CSA Cloud Controls Matrix and Consensus Assessment Initiative Questionnaire: FAQs
The CSA Cloud Controls Matrix and Consensus Assessment Initiative Q...
Published: 02/17/2024

Acknowledgements

Chris Shull
Chris Shull
Chief Information Security Officer

Chris Shull

Chief Information Security Officer

This person does not have a biography listed with CSA.

Michael Roza
Michael Roza
Head of Risk, Audit, Control and Compliance

Michael Roza

Head of Risk, Audit, Control and Compliance

Since 2012 Michael has contributed to over 100 CSA projects completed by CSA's Internet of Things, Zero Trust/Software-Defined Perimeter, Top Threats, Cloud Control Matrix, Containers/Microservices, DevSecOps, and other working groups. He has also served as co-chair of CSA's Enterprise Architecture, Top Threats, and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, SECaaS, and Cloud K...

Read more

Victor Chin Headshot Missing
Victor Chin

Victor Chin

This person does not have a biography listed with CSA.

Shawn Harris
Shawn Harris
Director of Information Security

Shawn Harris

Director of Information Security

With more than 25 years of information security experience, Shawn Harris is currently the Director of Information Security at Starbucks Coffee Company. His background includes engineering, architecture, and executive responsibilities. Shawn is currently co-chair of the CSA Cloud Controls Matrix working group, where he led efforts to develop the Cloud Control Matrix 4.0. Additionally, he has served on CSA’s Consensus Assessments ...

Read more

Angela Dogan
Angela Dogan
Director, Vendor Risk Management and Compliance Services, Lynx Technology Partners

Angela Dogan

Director, Vendor Risk Management and Compliance Services, Lynx Technology Partners

Angela Dogan is the Director, Vendor Risk Management and Compliance Services for Lynx Technology Partners. Previously, she served as Senior Project Manager for the Santa Fe Group and Vendor Auditor for Resurgent Capital Services.

With 15 years in the financial services industry, she is well-versed in standardized control frameworks such as those created by the Shared Assessments Program and Cloud Security Alliance, where she is a memb...

Read more

Reid Leake Headshot Missing
Reid Leake

Reid Leake

This person does not have a biography listed with CSA.

Erik Johnson
Erik Johnson
Cloud Security Specialist & Senior Research Analyst, CSA

Erik Johnson

Cloud Security Specialist & Senior Research Analyst, CSA

Worked for the Federal Reserve for many years and volunteered with the CSA with a focus on CCM/CAIQ V4, specifically the STA domain, and developing a comprehensive framework and guidance for defining and managing the cloud shared security responsibility model (SSRM).

I recently retired from the Federal Reserve and am now consulting with the CSA as a Senior Research Analyst with a focus on Zero Trust and Financial Services.

Linke...

Read more

Kevin Bugin Headshot Missing
Kevin Bugin

Kevin Bugin

This person does not have a biography listed with CSA.

Chris Shull
Chris Shull
Chief Information Security Officer

Chris Shull

Chief Information Security Officer

This person does not have a biography listed with CSA.

Andrew Williams
Andrew Williams
Director of Program Development, Coalfire

Andrew Williams

Director of Program Development, Coalfire

Andrew Williams is the Director of Program Development at Coalfire. In this role, he is responsible for working closely with Coalfire customers, industry bodies and regulatory authorities, and internal stakeholders to ensure Coalfire’s services, delivery, and talent are aligned to the needs of the future compliance and security landscape.

Andrew previously worked as practice director for Coalfire’s cloud assessment and risk advisory...

Read more

William Butler Headshot Missing
William Butler

William Butler

This person does not have a biography listed with CSA.

Douglas Barbin
Douglas Barbin
Principal and Cybersecurity Leader at Schellman & Company, LLC

Douglas Barbin

Principal and Cybersecurity Leader at Schellman & Company, LLC

This person does not have a biography listed with CSA.

Lawrence Martin Headshot Missing
Lawrence Martin

Lawrence Martin

This person does not have a biography listed with CSA.

Gaurav Khanna Headshot Missing
Gaurav Khanna

Gaurav Khanna

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training