ChaptersCircleEventsBlog
Align cybersecurity controls with evolving regulations and make a real impact in the industry. Join CSA's Regulatory Analysis and Compliance Engineering Working Group!

Download Publication

CSA CCM v3.0.1 Addendum - AICPA TSC 2017
CSA CCM v3.0.1 Addendum - AICPA TSC 2017

CSA CCM v3.0.1 Addendum - AICPA TSC 2017

Release Date: 08/03/2019

Working Group: Cloud Controls Matrix

This document is an addendum to the CCM V3.0.1 that contain controls mapping between the CSA CCM and the AICPA TSC 2017. The document aims to help AICPA TSC 2017 compliant organizations meet CCM requirements.

This is achieved by identifying compliance gaps in AICPA TSC 2017 in relation to the CCM. This document contains the following information:
• Controls Mapping
• Gap Analysis
• Gap Identification (i.e. Partial, Full or No Gap)
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
NIST CSF v2 Cloud Community Profile - Based on CCM v4
NIST CSF v2 Cloud Community Profile - Based on ...
Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2
Informative Reference Details for the Mapping o...
CCM-Lite and CAIQ-Lite
CCM-Lite and CAIQ-Lite
Why Do I Have to Fill Out a CAIQ Before Pursuing STAR Level 2 Certification?
Why Do I Have to Fill Out a CAIQ Before Pursuing STAR Level 2 Certi...
Published: 06/17/2025
Implementing CCM: Interoperability & Portability Controls
Implementing CCM: Interoperability & Portability Controls
Published: 06/13/2025
Valid-AI-ted: A Major Step Towards Real-Time Cloud Assurance
Valid-AI-ted: A Major Step Towards Real-Time Cloud Assurance
Published: 06/11/2025
Implementing CCM: Identity & Access Management Controls
Implementing CCM: Identity & Access Management Controls
Published: 05/30/2025

Acknowledgements

Chris Shull
Chris Shull
Chief Information Security Officer

Chris Shull

Chief Information Security Officer

Michael Roza
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Since 2012, Michael Roza has been a pivotal member of the Cloud Security Alliance (CSA) family. He has contributed to over 140 projects, as a Lead Author or Author/Contributor and many more as a Reviewer/Editor.

Michael's extensive contributions encompass critical areas including Artificial Intelligence, Zero Trust/Software Defined Perimeter, Internet of Things, Top Threats, Cloud Control Matrix, DevSecOps, and Key Management. His lea...

Read more

Victor Chin Headshot Missing
Victor Chin

Victor Chin

Shawn Harris
Shawn Harris
Director of Information Security

Shawn Harris

Director of Information Security

With more than 25 years of information security experience, Shawn Harris is currently the Director of Information Security at Starbucks Coffee Company. His background includes engineering, architecture, and executive responsibilities. Shawn is currently co-chair of the CSA Cloud Controls Matrix working group, where he led efforts to develop the Cloud Control Matrix 4.0. Additionally, he has served on CSA’s Consensus Assessments ...

Read more

Shahid Sharif Headshot Missing
Shahid Sharif

Shahid Sharif

Angela Dogan
Angela Dogan
Director, Vendor Risk Management and Compliance Services, Lynx Technology Partners

Angela Dogan

Director, Vendor Risk Management and Compliance Services, Lynx Technology Partners

Angela Dogan is the Director, Vendor Risk Management and Compliance Services for Lynx Technology Partners. Previously, she served as Senior Project Manager for the Santa Fe Group and Vendor Auditor for Resurgent Capital Services.

With 15 years in the financial services industry, she is well-versed in standardized control frameworks such as those created by the Shared Assessments Program and Cloud Security Alliance, where she is a memb...

Read more

Reid Leake Headshot Missing
Reid Leake

Reid Leake

Kimberley Laris Headshot Missing
Kimberley Laris

Kimberley Laris

Kevin Bugin Headshot Missing
Kevin Bugin

Kevin Bugin

Chris Shull
Chris Shull
Chief Information Security Officer

Chris Shull

Chief Information Security Officer

Ahmed Maaloul Headshot Missing
Ahmed Maaloul

Ahmed Maaloul

Audrey Katcher Headshot Missing
Audrey Katcher

Audrey Katcher

Keith Stocks Headshot Missing
Keith Stocks

Keith Stocks

Jeffrey Cook Headshot Missing
Jeffrey Cook

Jeffrey Cook

Debbie Zaller Headshot Missing
Debbie Zaller

Debbie Zaller

Siddharth Kantroo Headshot Missing
Siddharth Kantroo

Siddharth Kantroo

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training