ChaptersCircleEventsBlog
Align cybersecurity controls with evolving regulations and make a real impact in the industry. Join CSA's Regulatory Analysis and Compliance Engineering Working Group!

Download Publication

CSA CCM v3.0.1 Addendum - NIST 800-53 Rev 4 Moderate
CSA CCM v3.0.1 Addendum - NIST 800-53 Rev 4 Moderate

CSA CCM v3.0.1 Addendum - NIST 800-53 Rev 4 Moderate

Release Date: 08/03/2019

Working Group: Cloud Controls Matrix

This document is an addendum to the CCM V3.0.1 that contain controls mapping between the CSA CCM and the NIST 800-53 R4 Moderate Baseline. The document aims to help NIST 800-53 R4 Moderate compliant organizations meet CCM requirements. This is achieved by identifying compliance gaps in NIST 800-53 in relation to the CCM. This document contains the following information:
• Controls Mapping
• Gap Analysis
• Gap Identification (i.e. Partial, Full or No Gap)
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
NIST CSF v2 Cloud Community Profile - Based on CCM v4
NIST CSF v2 Cloud Community Profile - Based on ...
Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2
Informative Reference Details for the Mapping o...
CCM-Lite and CAIQ-Lite
CCM-Lite and CAIQ-Lite
Why Do I Have to Fill Out a CAIQ Before Pursuing STAR Level 2 Certification?
Why Do I Have to Fill Out a CAIQ Before Pursuing STAR Level 2 Certi...
Published: 06/17/2025
Implementing CCM: Interoperability & Portability Controls
Implementing CCM: Interoperability & Portability Controls
Published: 06/13/2025
Valid-AI-ted: A Major Step Towards Real-Time Cloud Assurance
Valid-AI-ted: A Major Step Towards Real-Time Cloud Assurance
Published: 06/11/2025
Implementing CCM: Identity & Access Management Controls
Implementing CCM: Identity & Access Management Controls
Published: 05/30/2025

Acknowledgements

William Butler Headshot Missing
William Butler

William Butler

Douglas Barbin
Douglas Barbin
Principal and Cybersecurity Leader at Schellman & Company, LLC

Douglas Barbin

Principal and Cybersecurity Leader at Schellman & Company, LLC

Michael Roza
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC

Michael Roza

Risk, Audit, Control and Compliance Professional at EVC

Michael Roza is a seasoned risk, audit, control and compliance, and cybersecurity professional with over 20 years of experience across multinational enterprises and startups. As a Cloud Security Alliance (CSA) Research member for over 10 years, he has led and contributed to more than 140 CSA projects spanning Zero Trust, AI, IoT, Top Threats, DecSecOps, Cloud Key Management, Cloud Control Matrix, and many others.

He has co-chaired...

Read more

Victor Chin Headshot Missing
Victor Chin

Victor Chin

Lawrence Martin Headshot Missing
Lawrence Martin

Lawrence Martin

Erik Johnson
Erik Johnson
Cloud Security Specialist & Senior Research Analyst, CSA

Erik Johnson

Cloud Security Specialist & Senior Research Analyst, CSA

Worked for the Federal Reserve for many years and volunteered with the CSA with a focus on CCM/CAIQ V4, specifically the STA domain, and developing a comprehensive framework and guidance for defining and managing the cloud shared security responsibility model (SSRM).

I recently retired from the Federal Reserve and am now consulting with the CSA as a Senior Research Analyst with a focus on Zero Trust and Financial Services.

Linke...

Read more

Chris Shull
Chris Shull
Chief Information Security Officer

Chris Shull

Chief Information Security Officer

Angela Dogan
Angela Dogan
Director, Vendor Risk Management and Compliance Services, Lynx Technology Partners

Angela Dogan

Director, Vendor Risk Management and Compliance Services, Lynx Technology Partners

Angela Dogan is the Director, Vendor Risk Management and Compliance Services for Lynx Technology Partners. Previously, she served as Senior Project Manager for the Santa Fe Group and Vendor Auditor for Resurgent Capital Services.

With 15 years in the financial services industry, she is well-versed in standardized control frameworks such as those created by the Shared Assessments Program and Cloud Security Alliance, where she is a memb...

Read more

Reid Leake Headshot Missing
Reid Leake

Reid Leake

Kevin Bugin Headshot Missing
Kevin Bugin

Kevin Bugin

Andrew Williams
Andrew Williams
Director of Program Development, Coalfire

Andrew Williams

Director of Program Development, Coalfire

Andrew Williams is the Director of Program Development at Coalfire. In this role, he is responsible for working closely with Coalfire customers, industry bodies and regulatory authorities, and internal stakeholders to ensure Coalfire’s services, delivery, and talent are aligned to the needs of the future compliance and security landscape.

Andrew previously worked as practice director for Coalfire’s cloud assessment and risk advisory...

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training