Working Group
Cloud Controls Matrix
Along with releasing updated versions of the CCM and CAIQ, this working group provides addendums, control mappings and gap analysis between the CCM and other research releases, industry standards, and regulations to keep it continually up to date.
Cloud Controls Matrix and CAIQ v4
Working Group Leadership

Daniele Catteddu
Chief Technology Officer, CSA
Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Eleftherios Skoutaris
AVP of GRC Solutions, CSA EMEA
Working Group Co-Chairs

Michael Roza
Risk, Audit, Control and Compliance Professional at EVC
Michael Roza is a seasoned risk, audit, control and compliance, and cybersecurity professional with over 20 years of experience across multinational enterprises and startups. As a Cloud Security Alliance (CSA) Research member for over 10 years, he has led and contributed to more than 140 CSA projects spanning Zero Trust, AI, IoT, Top Threats, DecSecOps, Cloud Key Management, Cloud Control Matrix, and many others.
He has co-chaired...

Akash Verma
Technical Program Manager, Continuous Assurance Engineering, Google
Akash Verma serves as the Technical Program Manager for Cybersecurity Continuous Assurance Engineering at Google, overseeing various security engineering programs within Google Cloud's continuous risk and compliance assurance endeavors.
Beyond his responsibilities at Google, Akash collaborates with industry experts to drive research and development initiatives aimed at advancing cybersecurity practices and standards, including, but no...

Siddharth Nandakishoran
Siddharth Nandakishoran serves as an FSI Assurance Specialist at Amazon Web Services (AWS), where he oversees the end-to-end customer audit journey of AWS, from initial due diligence to comprehensive audit execution. He specializes in helping financial services customers develop robust control assurance frameworks that align with regulatory requirements while leveraging AWS's cloud infrastructure.
With significant e...

Jon-Michael Brook
Jon-Michael C. Brook is a certified, 25-year practitioner of cybersecurity, cloud, and privacy. He is the principal contributor to certification sites for privacy and cloud security, and has published books on privacy. Jon-Michael received numerous awards and recognition during his time with Raytheon, Northrop Grumman, Symantec, and Starbucks. He holds patents and trade secrets in intrusion detection, GUI design, and semantic data redaction...
| Publications in Review | Open Until |
|---|---|
| Standards-Benchmarks-Maturity | Dec 13, 2025 |
| Open Source Red Teaming Tool: PyRIT Automation Capability in Agentic Red Team Testing Environments | Dec 13, 2025 |
| Using Zero Trust Against Identity Spoofing and Abuse | Dec 20, 2025 |
| Using Zero Trust to Secure Enterprise Information in LLM Environments | Dec 20, 2025 |
Who can join?
Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.
What is the time commitment?
The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.
Virtual Meetings
Attend our next meeting. You can just listen in to decide if this group is a good for you or you can choose to actively participate. During these calls we discuss current projects, and well as share ideas for new projects. This is a good way to meet the other members of the group. You can view all research meetings here.
Open Peer Reviews
Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.