Circle
Events
Blog

Download Publication

CCMv4.0 Auditing Guidelines
CCMv4.0 Auditing Guidelines
Who it's for:
  • auditors
  • cloud service providers
  • cloud customers

CCMv4.0 Auditing Guidelines

Release Date: 12/08/2021

This document contains auditing guidelines for each of the control specifications within the CCM version 4. The CCM is a detailed controls framework aligned with CSA’s Security Guidance for Critical Areas of Focus in Cloud Computing. Version 4, published in 2021, includes additional new components, such as the CCM v4.0 Implementation Guidelines and these auditing guidelines.

Within this document, you’ll find step-by-step instructions on how to audit each CCM v4.0 control. Auditors are provided with a set of assessment guidelines per CCMv4.0 control specification with an objective to improve the controls’ auditability and help organizations to more efficiently meet compliance (by conducting either internal or external 3rd party cloud security audits). 

Key Takeaways:
  • What the different CCM audit areas are
  • How to perform a CCM-related audit and assessment of organizations of any size, business, cloud deployment complexity, or maturity

Relevance to the Certificate of Cloud Auditing Knowledge (CCAK)
The CCMv4.0 Auditing Guidelines found in this document is an extension to the CCM Audit Workbook that appears in the CCAK guide. The workbook is a baseline audit template, auditors may wish to adopt in order to facilitate and guide a CCM audit. A major feature (among others) when filling out the workbook is for auditors to document how they will test whether the organization meets a given CCM control (that is to develop an audit test plan per CCM control). We took the audit workbook template, and based on that we developed auditing guidelines for all CCMv4.0 controls, something that is missing currently from the CCAK, and which significantly extends the relevant section.

Download this Resource

LoginCreate Account

Prefer to access this resource without an account? Download it now.

Acknowledgements

Vani Murthy Headshot
Vani Murthy
Senior advisor Security & Compliance at Akamai Technologies

Vani Murthy

Senior advisor Security & Compliance at Akamai Technologies

Vani has 20+ years of IT experience in the areas such as Security, Risk, Compliance, Cloud services (IaaS/PaaS/SaaS) architecture

Read more

Tanya Tipper-Luster Headshot
Tanya Tipper-Luster
Director, Cloud Security

Tanya Tipper-Luster

Director, Cloud Security

This person does not have a biography listed with CSA.

Renu Bedi Headshot
Renu Bedi
Manager-IT Security

Renu Bedi

Manager-IT Security

This person does not have a biography listed with CSA.

Robin Basham Headshot
Robin Basham
CEO

Robin Basham

CEO

Robin Basham recently lead the Cloud Security Alliance CCM 4 to NIST 800-53 R5 Working Group. This effort began as a proposed commitment in April, involving the collaboration of some of our biggest and most well respected East Bay Enterprises. Leveraging the talent of 20 volunteers and mappings as designed in three major companies, the CCM WG produced a refined mapping t...

Read more

Agnidipta Sarkar Headshot
Agnidipta Sarkar
Group CISO for Biocon Ltd.

Agnidipta Sarkar

Group CISO for Biocon Ltd.

Agnidipta Sarkar has been evangelizing Cybersecurity, Privacy, Business Continuity, Digital Resilience, and Standardization through speaking at industry forums like Gartner, IDC, EC-Council, ISMG, BCI Global, CORE Resilience, etc. and through his contributions to standards bodies like the ISO, Cloud Security Alliance, and the Business Continuity Institute. He is a member of ISO panels for security & privacy, continuity & resilience, and ris...

Read more

Michael Roza Headshot
Michael Roza
Risk, Audit, Control and Compliance Professional

Michael Roza

Risk, Audit, Control and Compliance Professional

Since 2012 Michael has contributed to over 75 CSA projects completed by CSA's Internet of Things, Blockchain/Distributed Ledger, Top Threats, Cloud Control Matrix, Software-Defined Perimeter, Applications, Containers, and Microservices, and other working groups. In, 2020 he also served as co-chair to CSA's Enterprise Architecture and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, S...

Read more

Ashish Vashishtha Headshot
Ashish Vashishtha
Cybersecurity - Sr. Risk Manager & Security Architect at IBM

Ashish Vashishtha

Cybersecurity - Sr. Risk Manager & Security Architect at IBM

Analytical, results-oriented IS/IT Audit, Governance, Risk, and Compliance (GRC) leader over 19 years of experience managing enterprise-wide IT/IS security risk approach for large healthcare and IT services organizations. Passionate design thinker with an ability to harness innovation by facilitating collaboration to develop enterprise-wide security risk assessments (onsite as well as remote) for high-risk Third-Parties leveraging NIST 800-...

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?