Download Publication

Who it's for:
- auditors
- cloud service providers
- cloud customers
CCMv4.0 Auditing Guidelines
Release Date: 12/08/2021
Working Group: Cloud Controls Matrix
This document contains auditing guidelines for each of the control specifications within the CCM version 4. The CCM is a detailed controls framework aligned with CSA’s Security Guidance for Critical Areas of Focus in Cloud Computing. Version 4, published in 2021, includes additional new components, such as the CCM v4.0 Implementation Guidelines and these auditing guidelines.
Within this document, you’ll find step-by-step instructions on how to audit each CCM v4.0 control. Auditors are provided with a set of assessment guidelines per CCMv4.0 control specification with an objective to improve the controls’ auditability and help organizations to more efficiently meet compliance (by conducting either internal or external 3rd party cloud security audits).
Key Takeaways:
- What the different CCM audit areas are
- How to perform a CCM-related audit and assessment of organizations of any size, business, cloud deployment complexity, or maturity
Relevance to the Certificate of Cloud Auditing Knowledge (CCAK)
The CCMv4.0 Auditing Guidelines found in this document is an extension to the CCM Audit Workbook that appears in the CCAK guide. The workbook is a baseline audit template, auditors may wish to adopt in order to facilitate and guide a CCM audit. A major feature (among others) when filling out the workbook is for auditors to document how they will test whether the organization meets a given CCM control (that is to develop an audit test plan per CCM control). We took the audit workbook template, and based on that we developed auditing guidelines for all CCMv4.0 controls, something that is missing currently from the CCAK, and which significantly extends the relevant section.
Download this Resource
Related Resources
Interested in helping develop research with CSA?
Related Certificates & Training
.png)
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more
Learn more
.jpeg)
.jpeg)

