There is a new version of the Cloud Controls Matrix available, you can find it here. You can learn about the transition timeline for v4.0 to v4.1, and how that will affect STAR Registry submissions in this blog.
The CCM is the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices, and regulations. CCM provides organizations with the needed structure, detail, and clarity relating to information security tailored to cloud computing. CCM is currently considered a de-facto standard for cloud security assurance and compliance.
_________________
What’s included in this CCM v4.0.13 download:
What’s included in this CCM v4.0.13 download:
- Guide to the CCM and CAIQ: This guide explains the individual components in this download file, their purpose, and how to use them.
- CCM + CAIQ v4: The latest version of the Cloud Controls Matrix and the Consensus Assessment Initiative Questionnaire.
- Mappings: Detailed mappings to various industry standards.
- CCM v4 Implementation Guidelines: Best practices for implementing the CCM.
- CCM v4 Auditing Guidelines: Steps and guidance for auditing against the CCM.
- Continuous Auditing Metrics: Catalog of security metrics for the cloud.
- STAR Level 1 Security Questionnaire (CAIQ v4): Use this to submit to the STAR Registry.
About the CAIQ versions in this file:
- CCM + CAIQ v4: This version is for reference only and cannot be submitted to the STAR Registry.
- STAR Level 1 Security Questionnaire (CAIQ v4): Submit this version to the STAR Registry.
Download this Resource




