Download Publication

Who it's for:
- auditors
- cloud service providers
- cloud customers
CCMv4.0 Auditing Guidelines
Release Date: 12/08/2021
Working Group: Cloud Controls Matrix Working Group
- What the different CCM audit areas are
- How to perform a CCM-related audit and assessment of organizations of any size, business, cloud deployment complexity, or maturity
Download this Resource
Acknowledgements

Vani Murthy
Senior advisor Security & Compliance at Akamai Technologies
Vani has 20+ years of IT experience in the areas such as Security, Risk, Compliance, Cloud services (IaaS/PaaS/SaaS) architecture

Tanya Tipper-Luster
Director, Cloud Security
This person does not have a biography listed with CSA.

Renu Bedi
Manager-IT Security
This person does not have a biography listed with CSA.

Robin Basham
CEO
Robin Basham recently lead the Cloud Security Alliance CCM 4 to NIST 800-53 R5 Working Group. This effort began as a proposed commitment in April, involving the collaboration of some of our biggest and most well respected East Bay Enterprises. Leveraging the talent of 20 volunteers and mappings as designed in three major companies, the CCM WG produced a refined mapping t...

Agnidipta Sarkar
Group CISO for Biocon Ltd.
Agnidipta Sarkar has been evangelizing Cybersecurity, Privacy, Business Continuity, Digital Resilience, and Standardization through speaking at industry forums like Gartner, IDC, EC-Council, ISMG, BCI Global, CORE Resilience, etc. and through his contributions to standards bodies like the ISO, Cloud Security Alliance, and the Business Continuity Institute. He is a member of ISO panels for security & privacy, continuity & resilience, and ris...

Michael Roza
Risk, Audit, Control and Compliance Professional
Since 2012 Michael has contributed to over 75 CSA projects completed by CSA's Internet of Things, Blockchain/Distributed Ledger, Top Threats, Cloud Control Matrix, Software-Defined Perimeter, Applications, Containers, and Microservices, and other working groups. In, 2020 he also served as co-chair to CSA's Enterprise Architecture and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, S...

Ashish Vashishtha
Cybersecurity - Sr. Risk Manager & Security Architect at IBM
Analytical, results-oriented IS/IT Audit, Governance, Risk, and Compliance (GRC) leader over 19 years of experience managing enterprise-wide IT/IS security risk approach for large healthcare and IT services organizations. Passionate design thinker with an ability to harness innovation by facilitating collaboration to develop enterprise-wide security risk assessments (onsite as well as remote) for high-risk Third-Parties leveraging NIST 800-...