ChaptersEventsBlog
Join Cyera’s DataSecAI in Dallas, Nov 12–14 to adopt, activate, and scale AI security for the future.

STAR Registry Listing for

IBM Office of the CISO

IBM Office of the CISO Logo
IBM Office of the CISO

IBM Office of the CISO

With IBM Cloud you have more ways to migrate, modernize and build innovative cloud apps today, and unlocking the value of all your data with analytics, machine learning, AI, and more. IBM Cloud services is a portfolio of hundreds of services built on the IBM Cloud and designed to meet the needs of customers worldwide. All IBM Cloud services are managed with a common security framework and part of a centralized ISO/IEC 27001 Certified Information Security Management System (ISMS) that provides an internationally recognized information security program and controls that are selected across industry best practices such as ISO/IEC 27002, 27017, 27018, NIST Special Publication 800-53r5, and others.

View other services by IBM Cloud:

Organizations who have the CSA Trusted Cloud Provider trustmark demonstrate a commitment to organizational security. They are a CSA Corporate Member, volunteer regularly for CSA, and have at least one staff member who has earned their CCSK.
A technology-neutral certification leveraging the requirements of the ISO/IEC 27001 management system standard together with the CSA Cloud Controls Matrix (CCM).
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about IBM Office of the CISO
Listed Since: 07/30/2018
Last Updated: 01/17/2025

STAR Level 1

Self-Assessment & Partner-Provided

Cloud Controls Matrix

CAIQ Self-assessment v4.0.3

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

STAR Level 2

Third-Party Audit

Organizations looking for a third-party audit can choose from one or more of the security and privacy audits and certifications.

Cloud Controls Matrix

STAR Certification (CCMv4)

A technology-neutral certification leveraging the requirements of the ISO/IEC 27001 management system standard together with the CSA Cloud Controls Matrix (CCM).