Download Publication
CCM v4.0 Addendum - ECUC PP v2.1
Release Date: 02/12/2024
Working Group: Cloud Controls Matrix
• Controls Mapping
• Gap Identification (i.e. Partial, Full or No Gap)
• Gap Analysis
The document is structured as follows. The tab 'CCMv4.0 - ECUC PPv2.1' contains the mappings as well as associated information such as the gap analysis and compensating controls. In this tab, columns:
• A-D contain the CCMv4.0 domains and control specifications.
• E-H contain the results of the mapping and gap analysis exercise.
The "Terminology" tab provides a list of terms used in this document and their definitions.
The CSA and the CCM working group hope that organizations will find this document useful for their cloud security compliance programs.
The contents of this document could contain technical inaccuracies, typographical errors and out-of-date information.
Download this Resource
Acknowledgements
Arpitha Kaushik
Senior Manager - Technical Risk
Arpitha is a certified expert in governance, risk, and compliance with over 15 years of experience in protecting critical systems and data for global enterprises. Her expertise includes auditing, risk management, compliance, third-party risk assessment, project management, cloud security, and AI governance & compliance. Additionally, she is an accredited CISA trainer and volunteers in research with CSA’s Cloud Control Matrix, and AI governa...
Karnika Sharma
Senior Business Analyst, Infosys
John B. Oseh
John B. Oseh, M.Eng, CISSP, CCSP, CISA, CRISC, CDPSE, CCAK, CCSK, APMP. Experienced information security consultant.
Ankit Sharma
Security Officer, Compute BU at Cisco Systems
Akash Verma
Technical Program Manager, Continuous Assurance Engineering, Google
Akash Verma serves as the Technical Program Manager for Cybersecurity Continuous Assurance Engineering at Google, overseeing various security engineering programs within Google Cloud's continuous risk and compliance assurance endeavors.
Beyond his responsibilities at Google, Akash collaborates with industry experts to drive research and development initiatives aimed at advancing cybersecurity practices and standards, including, but no...
Rajat Dubey
Cybersecurity Expert, Allianz Commercial
Rajat is an accomplished cybersecurity expert with over 13 years of experience safeguarding critical systems and data for global enterprises. His expertise spans cyber risk assessment, compliance, threat modeling, incident response, Penetration testing, Ethical hacking, Digital Forensic, Cloud Security and emerging technologies (AI, Blockchain, IoT, Quantum computing) for enhanced security.
Kerry Steele
Principal, Coalfire
Kerry Steele is a Principal at Coalfire, a leading cybersecurity advisory and assessment firm, where he provides strategic guidance and solutions for payments and cloud security. He has over 20 years of experience in information security, spanning various domains such as network security, endpoint security, application security, cloud architecture, cloud security, encryption, segmentation, identity and access management, penetration testing...
Interested in helping develop research with CSA?
Related Certificates & Training
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more