12% of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 you already have
CNCF Security Technical Advisory Group (TAG) already covers about 12% of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, leaving
174 of 197 controls as genuinely new work.
Already covered 21
Likely covered 2
New work 174
What is genuinely new work
Nothing in CNCF Security Technical Advisory Group (TAG) reaches these. This is the list to scope.
CCM-A&A-02Independent Assessments
CCM-A&A-03Risk Based Planning Assessment
CCM-A&A-04Requirements Compliance
CCM-A&A-05Audit Management Process
CCM-AIS-02Application Security Baseline Requirements
CCM-AIS-03Application Security Metrics
CCM-BCR-02Risk Assessment and Impact Analysis
CCM-BCR-03Business Continuity Strategy
CCM-BCR-04Business Continuity Planning
CCM-BCR-06Business Continuity Exercises
CCM-BCR-09Disaster Response Plan
CCM-BCR-10Response Plan Exercise
CCM-BCR-11Equipment Redundancy
CCM-CCC-02Quality Testing
CCM-CCC-03Change Management Technology
CCM-CCC-05Change Agreements
CCM-CCC-07Detection of Baseline Deviation
CCM-CCC-08Exception Management
CCM-CCC-09Change Restoration
CCM-CEK-01Encryption and Key Management Policy and Procedures
CCM-CEK-02CEK Roles and Responsibilities
CCM-CEK-04Encryption Algorithm
CCM-CEK-05Encryption Change Management
CCM-CEK-06Encryption Change Cost Benefit Analysis
CCM-CEK-07Encryption Risk Management
CCM-CEK-08CSC Key Management Capability
CCM-CEK-09Encryption and Key Management Audit
CCM-CEK-14Key Destruction
CCM-CEK-17Key Deactivation
CCM-CEK-21Key Inventory Management
CCM-DCS-01Off-Site Equipment Disposal Policy and Procedures
CCM-DCS-02Off-Site Transfer Authorization Policy and Procedures
CCM-DCS-03Secure Area Policy and Procedures
CCM-DCS-04Secure Media Transportation Policy and Procedures
CCM-DCS-05Assets Classification
CCM-DCS-06Assets Cataloguing and Tracking
CCM-DCS-07Controlled Access Points
CCM-DCS-08Equipment Identification
CCM-DCS-09Secure Area Authorization
CCM-DCS-10Surveillance System
CCM-DCS-11Unauthorized Access Response Training
CCM-DCS-12Cabling Security
CCM-DCS-13Environmental Systems
CCM-DCS-14Secure Utilities
CCM-DCS-15Equipment Location
CCM-DSP-01Security and Privacy Policy and Procedures
CCM-DSP-02Secure Disposal
CCM-DSP-04Data Classification
CCM-DSP-05Data Flow Documentation
CCM-DSP-06Data Ownership and Stewardship
CCM-DSP-07Data Protection by Design and Default
CCM-DSP-08Data Privacy by Design and Default
CCM-DSP-09Data Protection Impact Assessment
CCM-DSP-10Sensitive Data Transfer
CCM-DSP-11Personal Data Access, Reversal, Rectification and Deletion
CCM-DSP-12Limitation of Purpose in Personal Data Processing
CCM-DSP-13Personal Data Sub-processing
CCM-DSP-14Disclosure of Data Sub-processors
CCM-DSP-15Limitation of Production Data Use
CCM-DSP-16Data Retention and Deletion
CCM-DSP-17Sensitive Data Protection
CCM-DSP-18Disclosure Notification
CCM-GRC-02Risk Management Program
CCM-GRC-03Organizational Policy Reviews
CCM-GRC-04Policy Exception Process
CCM-GRC-06Governance Responsibility Model
CCM-GRC-08Special Interest Groups
CCM-HRS-01Background Screening Policy and Procedures
CCM-HRS-02Acceptable Use of Technology Policy and Procedures
CCM-HRS-03Clean Desk Policy and Procedures
CCM-HRS-04Remote and Home Working Policy and Procedures
CCM-HRS-06Employment Termination
CCM-HRS-07Employment Agreement Process
CCM-HRS-08Employment Agreement Content
CCM-HRS-09Personnel Roles and Responsibilities
CCM-HRS-10Non-Disclosure Agreements
CCM-HRS-11Security Awareness Training
CCM-HRS-12Personal and Sensitive Data Awareness and Training
CCM-HRS-13Compliance User Responsibility
CCM-IAM-02Strong Password Policy and Procedures
CCM-IAM-03Identity Inventory
CCM-IAM-04Separation of Duties
CCM-IAM-06User Access Provisioning
CCM-IAM-07User Access Changes and Revocation
CCM-IAM-08User Access Review
CCM-IAM-09Segregation of Privileged Access Roles
CCM-IAM-10Management of Privileged Access Roles
CCM-IAM-11CSCs Approval for Agreed Privileged Access Roles
CCM-IAM-12Safeguard Logs Integrity
CCM-IAM-13Uniquely Identifiable Users
CCM-IAM-14Strong Authentication
CCM-IAM-15Passwords Management
CCM-IAM-16Authorization Mechanisms
CCM-IPY-01Interoperability and Portability Policy and Procedures
CCM-IPY-02Application Interface Availability
CCM-IPY-03Secure Interoperability and Portability Management
CCM-IPY-04Data Portability Contractual Obligations
CCM-IVS-01Infrastructure and Virtualization Security Policy and Procedures
CCM-IVS-02Capacity and Resource Planning
CCM-IVS-05Production and Non-Production Environments
CCM-IVS-06Segmentation and Segregation
CCM-IVS-07Migration to Cloud Environments
CCM-IVS-08Network Architecture Documentation
CCM-IVS-09Network Defense
CCM-LOG-01Logging and Monitoring Policy and Procedures
CCM-LOG-02Audit Logs Protection
CCM-LOG-04Audit Logs Access and Accountability
CCM-LOG-05Audit Logs Monitoring and Response
CCM-LOG-06Clock Synchronization
CCM-LOG-10Encryption Monitoring and Reporting
CCM-LOG-11Transaction/Activity Logging
CCM-LOG-12Access Control Logs
CCM-LOG-13Failures and Anomalies Reporting
CCM-SEF-01Security Incident Management Policy and Procedures
CCM-SEF-02Service Management Policy and Procedures
CCM-SEF-04Incident Response Testing
CCM-SEF-05Incident Response Metrics
CCM-SEF-06Event Triage Processes
CCM-SEF-07Security Breach Notification
CCM-SEF-08Points of Contact Maintenance
CCM-STA-01SSRM Policy and Procedures
CCM-STA-02SSRM Supply Chain
CCM-STA-04SSRM Control Ownership
CCM-STA-05SSRM Documentation Review
CCM-STA-06SSRM Control Implementation
CCM-STA-07Supply Chain Inventory
CCM-STA-09Primary Service and Contractual Agreement
CCM-STA-10Supply Chain Agreement Review
CCM-STA-11Internal Compliance Testing
CCM-STA-12Supply Chain Service Agreement Compliance
CCM-STA-13Supply Chain Governance Review
CCM-STA-14Supply Chain Data Security Assessment
CCM-TVM-02Malware Protection Policy and Procedures
CCM-TVM-04Detection Updates
CCM-TVM-05External Library Vulnerabilities
CCM-TVM-06Penetration Testing
CCM-TVM-07Vulnerability Identification
CCM-TVM-08Vulnerability Prioritization
CCM-TVM-09Vulnerability Management Reporting
CCM-TVM-10Vulnerability Management Metrics
CCM-UEM-01Endpoint Devices Policy and Procedures
CCM-UEM-02Application and Service Approval
CCM-UEM-04Endpoint Inventory
CCM-UEM-05Endpoint Management
CCM-UEM-06Automatic Lock Screen
CCM-UEM-07Operating Systems
CCM-UEM-08Storage Encryption
CCM-UEM-09Anti-Malware Detection and Prevention
CCM-UEM-10Software Firewall
CCM-UEM-11Data Loss Prevention
CCM-UEM-14Third-Party Endpoint Security Posture
Show the 23 you already have
CCM-A&A-01Audit and Assurance Policy and Procedures
CCM-AIS-01Application and Interface Security Policy and Procedures
CCM-AIS-04Secure Application Design and Development
CCM-AIS-05Automated Application Security Testing
CCM-AIS-06Automated Secure Application Deployment
CCM-BCR-01Business Continuity Management Policy and Procedures
CCM-CCC-01Change Management Policy and Procedures
CCM-CCC-04Unauthorized Change Protection
CCM-CCC-06Change Management Baseline
CCM-CEK-03Data Encryption
CCM-GRC-01Governance Program Policy and Procedures
CCM-GRC-05Information Security Program
CCM-GRC-07Information System Regulatory Mapping
CCM-IAM-01Identity and Access Management Policy and Procedures
CCM-IAM-05Least Privilege
CCM-IVS-03Network Security
CCM-IVS-04OS Hardening and Base Controls
CCM-LOG-03Security Monitoring and Alerting
CCM-SEF-03Incident Response Plans
CCM-STA-08Supply Chain Risk Management
CCM-TVM-03Vulnerability Remediation Schedule
CCM-AIS-07Application Vulnerability Remediation
CCM-TVM-01Threat and Vulnerability Management Policy and Procedures
How this is calculated
Already covered means a mapping runs from a control in CNCF Security Technical Advisory Group (TAG) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition