Cloud 101CircleEventsBlog
CSA's Continuous Audit Metrics Working Group is expanding! Help shape the future of cloud assurance.

Download Publication

CCM v4.0 Addendum - ECUC PP v2.1
CCM v4.0 Addendum - ECUC PP v2.1

CCM v4.0 Addendum - ECUC PP v2.1

Release Date: 02/12/2024

This document is an addendum to the 'ECUC Position Paper v2.1 (ECUC PP v2.1) that contains controls mapping between the CSA CCM v4.0 and the ECUC PPv2.1. The document aims to help ECUC PPv2.1 compliant organizations meet CCM v4.0 requirements. This is achieved by identifying compliance gaps in ECUC PPv2.1 in relation to the CCM v4.0. This document contains the following information:
  • Controls Mapping 
  • Gap Identification (i.e. Partial, Full or No Gap)
  • Gap Analysis
 
The document is structured as follows. The tab 'CCMv4.0 - ECUC PPv2.1' contains the mappings as well as associated information such as the gap analysis and compensating controls. In this tab, columns:
• A-D contain the CCMv4.0 domains and control specifications.
• E-H contain the results of the mapping and gap analysis exercise.

The "Terminology" tab provides a list of terms used in this document and their definitions.
 
The CSA and the CCM working group hope that organizations will find this document useful for their cloud security compliance programs.
The contents of this document could contain technical inaccuracies, typographical errors and out-of-date information.

Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
CSA CCM v4.0 Addendum - IBM Cloud Framework for Financial Services v1.1.0
CSA CCM v4.0 Addendum - IBM Cloud Framework for...
CSA CCM v4.0 Addendum - CRI FS Profile v1.2
CSA CCM v4.0 Addendum - CRI FS Profile v1.2
CCMv4.0 Auditing Guidelines
CCMv4.0 Auditing Guidelines
A New Era of Data Protection: CSA’s Strategic Partnership with the EU Cloud CoC for GDPR Compliance
A New Era of Data Protection: CSA’s Strategic Partnership with the ...
Published: 02/29/2024
The CSA Cloud Controls Matrix and Consensus Assessment Initiative Questionnaire: FAQs
The CSA Cloud Controls Matrix and Consensus Assessment Initiative Q...
Published: 02/17/2024
2024: A Critical Year for the Cloud Security Teenager
2024: A Critical Year for the Cloud Security Teenager
Published: 12/29/2023
Applying the AIS Domain of the CCM to Generative AI
Applying the AIS Domain of the CCM to Generative AI
Published: 12/22/2023

Acknowledgements

Arpitha Kaushik
Arpitha Kaushik

Arpitha Kaushik

This person does not have a biography listed with CSA.

Ankit Sharma
Ankit Sharma
Engineering Technical Leader at Cisco Systems India Pvt Ltd

Ankit Sharma

Engineering Technical Leader at Cisco Systems India Pvt Ltd

This person does not have a biography listed with CSA.

Karnika Sharma
Karnika Sharma
Senior Business Analyst, Infosys

Karnika Sharma

Senior Business Analyst, Infosys

This person does not have a biography listed with CSA.

Akash Verma
Akash Verma
Technical Program Manager, Continuous Assurance Engineering, Google

Akash Verma

Technical Program Manager, Continuous Assurance Engineering, Google

Akash Verma serves as the Technical Program Manager for Continuous Assurance Engineering (CAE) at Google, overseeing various security tooling programs within Google Cloud's continuous risk and controls assurance endeavors.

Beyond his responsibilities at Google, Akash collaborates with industry experts to drive research and development initiatives aimed at advancing cybersecurity practices.

With an extensive career spanning more ...

Read more

Rajat Dubey
Rajat Dubey
Cybersecurity Expert, Allianz Commercial

Rajat Dubey

Cybersecurity Expert, Allianz Commercial

Rajat is an accomplished cybersecurity expert with over 13 years of experience safeguarding critical systems and data for global enterprises. His expertise spans cyber risk assessment, compliance, threat modeling, incident response, Penetration testing, Ethical hacking, Digital Forensic, Cloud Security and emerging technologies (AI, Blockchain, IoT, Quantum computing) for enhanced security.

Read more

John B. Oseh
John B. Oseh

John B. Oseh

John B. Oseh, M.Eng, CISSP, CCSP, CISA, CRISC, CDPSE, CCAK, CCSK, APMP. Experienced information security consultant.

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training