Cloud 101CircleEventsBlog
Register for CSA's Virtual AI Summit to discover AI's business impact, tackle security challenges, and ensure compliance with evolving regulations.

Download Publication

The Continuous Audit Metrics Catalog: Towards a Machine-Readable Representation
The Continuous Audit Metrics Catalog: Towards a Machine-Readable Representation

The Continuous Audit Metrics Catalog: Towards a Machine-Readable Representation

Release Date: 06/07/2022

In October 2021, the Cloud Security Alliance released the first version of the Continuous Audit Metrics catalog which provides a standard reference for the continuous auditing of cloud services that supports security metrics in a way that mirrors what the CSA CCM or ISO/IEC 27002 does for security controls. The released catalog contained an initial set of 34 security metrics, each mapped to the CCM v4


This document takes the initial catalog that was presented in PDF format and translates of the 34 security metrics into YAML, a machine-readable format that is also still reasonably easy to understand by humans. 

Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
The Continuous Audit Metrics Catalog
The Continuous Audit Metrics Catalog
Mastering Security Compliance with Continuous Controls Monitoring
Mastering Security Compliance with Continuous Controls Monitoring
Published: 01/02/2025
Winning at Regulatory Roulette: Innovations Shaping the Future of GRC
Winning at Regulatory Roulette: Innovations Shaping the Future of GRC
Published: 12/19/2024
Vulnerability Management Isn't About Finding Issues — It's About Fixing Them in Context
Vulnerability Management Isn't About Finding Issues — It's About Fi...
Published: 12/13/2024
Why Continuous Controls Monitoring is Not GRC: Transforming Compliance and Risk Management
Why Continuous Controls Monitoring is Not GRC: Transforming Complia...
Published: 12/09/2024

Acknowledgements

Hafiz Sheikh Adnan Ahmed
Hafiz Sheikh Adnan Ahmed

Hafiz Sheikh Adnan Ahmed

Hafiz Sheikh Adnan Ahmed is a futurist and technology/Security leader with 17+ years track record in the areas of ICT Governance, Cyber Security & Resilience, Data Privacy & Protection, Risk Management, Corporate Excellence & Innovation, Digital Transformation, Strategic Transformation.

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training