Download Publication
NIST CSF v2 Cloud Community Profile - Based on CCM v4
Release Date: 10/15/2024
The CSFv2.0 Cloud Community Profile aligns the Cloud Controls Matrix (CCM) version 4.0 with the Cybersecurity Framework (CSF) version 2.0 by mapping equivalent security requirements between the two frameworks. It also aims to pinpoint CCMv4 cloud security requirements that are not covered in CSFv2.0. The missing cloud security requirements in CSFv2.0 are addressed through an "addendum" (see "column F"), which lists the additional cloud-specific requirements alongside the relevant CSF subcategories.
By integrating these addenda into their existing CSFv2.0 implementation, organizations can effectively meet both CSF and CCMv4 requirements, enhance their cloud security posture, de-risk their cloud environments, and streamline compliance with both frameworks.
By integrating these addenda into their existing CSFv2.0 implementation, organizations can effectively meet both CSF and CCMv4 requirements, enhance their cloud security posture, de-risk their cloud environments, and streamline compliance with both frameworks.
Download this Resource
Prefer to access this resource without an account? Download it now.
Are you a research volunteer? Request to have your profile displayed on the website here.
Interested in helping develop research with CSA?
Related Certificates & Training
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more