40% of APRA CPS 230 Operational Risk Management you already have
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 already covers about 40% of APRA CPS 230 Operational Risk Management, leaving
28 of 47 controls as genuinely new work.
Already covered 0
Likely covered 19
New work 28
No control in Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
maps directly to one in APRA CPS 230 Operational Risk Management. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 reaches these. This is the list to scope.
CPS230-10Operational Risk Management Policy
CPS230-13Board Accountability
CPS230-14Senior Management Roles
CPS230-15Operational Risk Framework
CPS230-17Critical Operations Identification
CPS230-18Critical Operations Register
CPS230-19Critical Operation Tolerance Levels
CPS230-32Dependencies Identification
CPS230-34Tailored Testing Programs
CPS230-36Tolerance Levels for Disruption
CPS230-39Material Service Provider Identification
CPS230-40Material Classification
CPS230-42APRA Classification Power
CPS230-45APRA Access Provisions
CPS230-47Monitoring and Reporting
CPS230-48Service Provider Due Diligence
CPS230-53Service Provider Monitoring
CPS230-57Concentration Risk
CPS230-60APRA Notification of Provider Arrangements
CPS230-63Operational Risk Reporting
CPS230-66Independent Review
CPS230-7Board Responsibility
CPS230-8Board Tolerance Levels
CPS230-9Senior Management Accountability
Show the 19 you already have
CPS230-11Risk Identification and Assessment
CPS230-12Internal Controls and Systems
CPS230-16Internal Audit Review
CPS230-20Capability to Remain Within Tolerance
CPS230-22Vulnerability and Gap Identification
CPS230-24Internal Controls
CPS230-25Business Continuity Policy
CPS230-26Business Continuity Plans
CPS230-27Incident Management
CPS230-28Recovery Objectives
CPS230-29Communication Plans
CPS230-31Escalation Procedures
CPS230-37Service Provider Management Policy
CPS230-38Business Continuity Plan
CPS230-44Service Provider Risk Identification
CPS230-46Ongoing Risk Management
CPS230-49Internal Audit of Service Providers
CPS230-50Service Provider Contracts
CPS230-70Change Management
How this is calculated
Already covered means a mapping runs from a control in Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition