Cloud 101CircleEventsBlog
Join us for Cybersecurity Awareness Month! Strengthen your cyber resilience with essential security tips and resources for everyone.

Download Publication

CCM v4.0 Addendum - ECUC PP v2.1
CCM v4.0 Addendum - ECUC PP v2.1

CCM v4.0 Addendum - ECUC PP v2.1

Release Date: 02/12/2024

Working Group: Cloud Controls Matrix

This document is an addendum to the 'ECUC Position Paper v2.1 (ECUC PP v2.1) that contains controls mapping between the CSA CCM v4.0 and the ECUC PPv2.1. The document aims to help ECUC PPv2.1 compliant organizations meet CCM v4.0 requirements. This is achieved by identifying compliance gaps in ECUC PPv2.1 in relation to the CCM v4.0. This document contains the following information:
  • Controls Mapping 
  • Gap Identification (i.e. Partial, Full or No Gap)
  • Gap Analysis
 
The document is structured as follows. The tab 'CCMv4.0 - ECUC PPv2.1' contains the mappings as well as associated information such as the gap analysis and compensating controls. In this tab, columns:
• A-D contain the CCMv4.0 domains and control specifications.
• E-H contain the results of the mapping and gap analysis exercise.

The "Terminology" tab provides a list of terms used in this document and their definitions.
 
The CSA and the CCM working group hope that organizations will find this document useful for their cloud security compliance programs.
The contents of this document could contain technical inaccuracies, typographical errors and out-of-date information.

Download this Resource

Bookmark
Share
Related resources
CCM-Lite and CAIQ-Lite
CCM-Lite and CAIQ-Lite
CCM v4.0 Implementation Guidelines
CCM v4.0 Implementation Guidelines
Cloud Controls Matrix and CAIQ v4
Cloud Controls Matrix and CAIQ v4
CSA Community Spotlight: Bolstering the Mission of Cybersecurity with CEO Avani Desai
CSA Community Spotlight: Bolstering the Mission of Cybersecurity wi...
Published: 10/02/2024
Implementing the Shared Security Responsibility Model in the Cloud
Implementing the Shared Security Responsibility Model in the Cloud
Published: 09/27/2024
What is the CSA STAR Program? An Intro for Beginners
What is the CSA STAR Program? An Intro for Beginners
Published: 09/24/2024
Discover Cloud Security Services That are Enabled with CSA STAR
Discover Cloud Security Services That are Enabled with CSA STAR
Published: 09/06/2024
Know Your Exposure: Is Your Cloud Data Secure in the Age of AI?
Know Your Exposure: Is Your Cloud Data Secure in the Age of AI?
November 6 | Online
Smart SOC 2: Automating Compliance with Drata and AWS
Smart SOC 2: Automating Compliance with Drata and AWS
November 12 | Online

Acknowledgements

Arpitha Kaushik
Arpitha Kaushik
Senior Manager - Technical Risk

Arpitha Kaushik

Senior Manager - Technical Risk

Arpitha is a certified expert in governance, risk, and compliance with over 15 years of experience in protecting critical systems and data for global enterprises. Her expertise includes auditing, risk management, compliance, third-party risk assessment, project management, cloud security, and AI governance & compliance. Additionally, she is an accredited CISA trainer and volunteers in research with CSA’s Cloud Control Matrix, and AI governa...

Read more

Karnika Sharma
Karnika Sharma
Senior Business Analyst, Infosys

Karnika Sharma

Senior Business Analyst, Infosys

John B. Oseh
John B. Oseh

John B. Oseh

John B. Oseh, M.Eng, CISSP, CCSP, CISA, CRISC, CDPSE, CCAK, CCSK, APMP. Experienced information security consultant.

Read more

Ankit Sharma
Ankit Sharma
Security Officer, Compute BU at Cisco Systems

Ankit Sharma

Security Officer, Compute BU at Cisco Systems

Akash Verma
Akash Verma
Technical Program Manager, Continuous Assurance Engineering, Google

Akash Verma

Technical Program Manager, Continuous Assurance Engineering, Google

Akash Verma serves as the Technical Program Manager for Cybersecurity Continuous Assurance Engineering at Google, overseeing various security engineering programs within Google Cloud's continuous risk and compliance assurance endeavors.

Beyond his responsibilities at Google, Akash collaborates with industry experts to drive research and development initiatives aimed at advancing cybersecurity practices and standards, including, but no...

Read more

Rajat Dubey
Rajat Dubey
Cybersecurity Expert, Allianz Commercial

Rajat Dubey

Cybersecurity Expert, Allianz Commercial

Rajat is an accomplished cybersecurity expert with over 13 years of experience safeguarding critical systems and data for global enterprises. His expertise spans cyber risk assessment, compliance, threat modeling, incident response, Penetration testing, Ethical hacking, Digital Forensic, Cloud Security and emerging technologies (AI, Blockchain, IoT, Quantum computing) for enhanced security.

Read more

Kerry Steele
Kerry Steele
Principal, Coalfire

Kerry Steele

Principal, Coalfire

Kerry Steele is a Principal at Coalfire, a leading cybersecurity advisory and assessment firm, where he provides strategic guidance and solutions for payments and cloud security. He has over 20 years of experience in information security, spanning various domains such as network security, endpoint security, application security, cloud architecture, cloud security, encryption, segmentation, identity and access management, penetration testing...

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training