Circle
Events
Blog

Download Publication

CCM v4.0 Implementation Guidelines
CCM v4.0 Implementation Guidelines

CCM v4.0 Implementation Guidelines

Release Date: 09/13/2021

This document will help you understand how to navigate through the Cloud Controls Matrix v4 to use it effectively and interpret and implement the CCM control specifications.  The document’s main goal is to support the implementation of CCM controls and provide guidance in the form of recommendations on how that can be properly achieved per each CCM control specification. 

The CCM Implementation guidelines are a collaborative product from volunteering subject matter experts within the CCM Working Group. It is based on the shared experiences of both cloud providers and cloud customers in implementing and securing cloud services when leveraging the CCM controls.

The guidelines are also available in a spreadsheet format, where they can be leveraged alongside the rest of the CCMv4 components.



Help CSA better understand how we can support the cloud community. Answer a couple of questions to download this resource.

In my current job I work in:

Can we send you updates?

By opting into this agreement I am indicating that I want to receive email updates from CSA on related projects. (Marketing purposes, Section 3 of the Privacy Policy).

You’ve made safer cloud computing possible.

Download
Provide feedback on this form

CSA is a community driven organization. We would like to send you updates about our ongoing initiatives and opportunities to participate.

By opting into this agreement I am indicating that I want to receive email updates from CSA on related projects. (Marketing purposes, Section 3 of the Privacy Policy).

Download
Provide feedback on this form

Acknowledgements

Vani Murthy Headshot
Vani Murthy
Senior advisor Security & Compliance at Akamai Technologies
Vani Murthy

Senior advisor Security & Compliance at Akamai Technologies

Vani is an active contributor to several Cloud Security Alliance working groups, including Application Containers and Microservices, Serverless, Top threats, Cloud Control Matrix (CCMv4), SDP Expert Group (Advisory Group to the Office of the CTO), Cloud Key Management etc. Vani has co-authored publications such as "How to Design a Secure Serverless Architecture", "CCM v4.0 Implementation Guidelines", "Cloud Top Threats". She has...

Read more

Johan Olivier Headshot
Johan Olivier
Security and Compliance Director
Johan Olivier

Security and Compliance Director

I am the Security and Compliance Director at Qorus Software where I am responsible for driving security and privacy compliance across the business. My career in the compliance space is backed by 22 years of experience as a Software Solutions Architect. Having worked in seven countries across four continents I have developed a special interest in behavioral sciences, psychology, diversity, and inclusion in the workplace. I am a motivational ...

Read more

Geoff Bird Headshot
Geoff Bird
Chief Information Security Officer
Geoff Bird

Chief Information Security Officer

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?