ChaptersEventsBlog

Download Publication

Enterprise Architecture to CCM Shared Responsibility Model
Enterprise Architecture to CCM Shared Responsibility Model

Enterprise Architecture to CCM Shared Responsibility Model

Release Date: 12/18/2020

The EA-CCM Shared Responsibility Model is a companion piece with the EA-CCM Mapping.

The Enterprise Architecture working group's Enterprise Reference Architecture (ERA) is both a methodology and a set of tools enabling security architects, enterprise architects and GRC professionals to leverage a common set of solutions that fulfill their common needs. The expectation is the ERA will assist in assessments where their internal IT and their cloud providers are in terms of security capabilities and roadmap planning to meet the security needs of their business. The ERA provides a security viewpoint on a typical Enterprise Architecture, thus taking a domain-based approach covering Business Operations, IT Operations, Security and Risk Management as well as the classic layered architecture of Presentation, Application, Information, and Infrastructure domains.

The mapping of CCM controls per the Shared Responsibility Model according to the following service levels - IaaS, PaaS, SaaS. It is intended to give the reader an overview of cloud responsibility with the specific control domain from the view of either the cloud service provider and/or the cloud consumer. 0 (zero) signifies no responsibility, whereas the placement of a 1 (one) signifies the given responsibility. From here, the reader can map that control domain back to the CCM control for further guidance and architecture.
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
Introductory Guidance to AICM
Introductory Guidance to AICM
Capabilities-Based Risk Assessment (CBRA) for AI Systems
Capabilities-Based Risk Assessment (CBRA) for A...
AICM Implementation & Auditing Guidelines (Frameworks)
AICM Implementation & Auditing Guidelines (Fram...
How Organizations are Addressing Cloud Investigation and Response
How Organizations are Addressing Cloud Investigation and Response
Published: 01/22/2026
Beyond Badge-Selling: Why Compliance Automation Needs Trust by Design
Beyond Badge-Selling: Why Compliance Automation Needs Trust by Design
Published: 01/21/2026
Scoping a Privacy Information Management System (PIMS) With ISO 27701:2025
Scoping a Privacy Information Management System (PIMS) With ISO 277...
Published: 01/21/2026
What Actually Makes an Agentic AI Solution Scalable?
What Actually Makes an Agentic AI Solution Scalable?
Published: 01/20/2026

Interested in helping develop research with CSA?

Related Certificates & Training