Framework overlap

Does CNCF Security Technical Advisory Group (TAG) cover Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1?

You hold CNCF Security Technical Advisory Group (TAG) and have been told to do Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1. Here is how much overlaps, control by control.

12% of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 you already have

CNCF Security Technical Advisory Group (TAG) already covers about 12% of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, leaving 174 of 197 controls as genuinely new work.

Already covered 21 Likely covered 2 New work 174

What is genuinely new work

Nothing in CNCF Security Technical Advisory Group (TAG) reaches these. This is the list to scope.

CCM-A&A-02
Independent Assessments
CCM-A&A-03
Risk Based Planning Assessment
CCM-A&A-04
Requirements Compliance
CCM-A&A-05
Audit Management Process
CCM-A&A-06
Remediation
CCM-AIS-02
Application Security Baseline Requirements
CCM-AIS-03
Application Security Metrics
CCM-BCR-02
Risk Assessment and Impact Analysis
CCM-BCR-03
Business Continuity Strategy
CCM-BCR-04
Business Continuity Planning
CCM-BCR-05
Documentation
CCM-BCR-06
Business Continuity Exercises
CCM-BCR-07
Communication
CCM-BCR-08
Backup
CCM-BCR-09
Disaster Response Plan
CCM-BCR-10
Response Plan Exercise
CCM-BCR-11
Equipment Redundancy
CCM-CCC-02
Quality Testing
CCM-CCC-03
Change Management Technology
CCM-CCC-05
Change Agreements
CCM-CCC-07
Detection of Baseline Deviation
CCM-CCC-08
Exception Management
CCM-CCC-09
Change Restoration
CCM-CEK-01
Encryption and Key Management Policy and Procedures
CCM-CEK-02
CEK Roles and Responsibilities
CCM-CEK-04
Encryption Algorithm
CCM-CEK-05
Encryption Change Management
CCM-CEK-06
Encryption Change Cost Benefit Analysis
CCM-CEK-07
Encryption Risk Management
CCM-CEK-08
CSC Key Management Capability
CCM-CEK-09
Encryption and Key Management Audit
CCM-CEK-10
Key Generation
CCM-CEK-11
Key Purpose
CCM-CEK-12
Key Rotation
CCM-CEK-13
Key Revocation
CCM-CEK-14
Key Destruction
CCM-CEK-15
Key Activation
CCM-CEK-16
Key Suspension
CCM-CEK-17
Key Deactivation
CCM-CEK-18
Key Archival
CCM-CEK-19
Key Compromise
CCM-CEK-20
Key Recovery
CCM-CEK-21
Key Inventory Management
CCM-DCS-01
Off-Site Equipment Disposal Policy and Procedures
CCM-DCS-02
Off-Site Transfer Authorization Policy and Procedures
CCM-DCS-03
Secure Area Policy and Procedures
CCM-DCS-04
Secure Media Transportation Policy and Procedures
CCM-DCS-05
Assets Classification
CCM-DCS-06
Assets Cataloguing and Tracking
CCM-DCS-07
Controlled Access Points
CCM-DCS-08
Equipment Identification
CCM-DCS-09
Secure Area Authorization
CCM-DCS-10
Surveillance System
CCM-DCS-11
Unauthorized Access Response Training
CCM-DCS-12
Cabling Security
CCM-DCS-13
Environmental Systems
CCM-DCS-14
Secure Utilities
CCM-DCS-15
Equipment Location
CCM-DSP-01
Security and Privacy Policy and Procedures
CCM-DSP-02
Secure Disposal
CCM-DSP-03
Data Inventory
CCM-DSP-04
Data Classification
CCM-DSP-05
Data Flow Documentation
CCM-DSP-06
Data Ownership and Stewardship
CCM-DSP-07
Data Protection by Design and Default
CCM-DSP-08
Data Privacy by Design and Default
CCM-DSP-09
Data Protection Impact Assessment
CCM-DSP-10
Sensitive Data Transfer
CCM-DSP-11
Personal Data Access, Reversal, Rectification and Deletion
CCM-DSP-12
Limitation of Purpose in Personal Data Processing
CCM-DSP-13
Personal Data Sub-processing
CCM-DSP-14
Disclosure of Data Sub-processors
CCM-DSP-15
Limitation of Production Data Use
CCM-DSP-16
Data Retention and Deletion
CCM-DSP-17
Sensitive Data Protection
CCM-DSP-18
Disclosure Notification
CCM-DSP-19
Data Location
CCM-GRC-02
Risk Management Program
CCM-GRC-03
Organizational Policy Reviews
CCM-GRC-04
Policy Exception Process
CCM-GRC-06
Governance Responsibility Model
CCM-GRC-08
Special Interest Groups
CCM-HRS-01
Background Screening Policy and Procedures
CCM-HRS-02
Acceptable Use of Technology Policy and Procedures
CCM-HRS-03
Clean Desk Policy and Procedures
CCM-HRS-04
Remote and Home Working Policy and Procedures
CCM-HRS-05
Asset returns
CCM-HRS-06
Employment Termination
CCM-HRS-07
Employment Agreement Process
CCM-HRS-08
Employment Agreement Content
CCM-HRS-09
Personnel Roles and Responsibilities
CCM-HRS-10
Non-Disclosure Agreements
CCM-HRS-11
Security Awareness Training
CCM-HRS-12
Personal and Sensitive Data Awareness and Training
CCM-HRS-13
Compliance User Responsibility
CCM-IAM-02
Strong Password Policy and Procedures
CCM-IAM-03
Identity Inventory
CCM-IAM-04
Separation of Duties
CCM-IAM-06
User Access Provisioning
CCM-IAM-07
User Access Changes and Revocation
CCM-IAM-08
User Access Review
CCM-IAM-09
Segregation of Privileged Access Roles
CCM-IAM-10
Management of Privileged Access Roles
CCM-IAM-11
CSCs Approval for Agreed Privileged Access Roles
CCM-IAM-12
Safeguard Logs Integrity
CCM-IAM-13
Uniquely Identifiable Users
CCM-IAM-14
Strong Authentication
CCM-IAM-15
Passwords Management
CCM-IAM-16
Authorization Mechanisms
CCM-IPY-01
Interoperability and Portability Policy and Procedures
CCM-IPY-02
Application Interface Availability
CCM-IPY-03
Secure Interoperability and Portability Management
CCM-IPY-04
Data Portability Contractual Obligations
CCM-IVS-01
Infrastructure and Virtualization Security Policy and Procedures
CCM-IVS-02
Capacity and Resource Planning
CCM-IVS-05
Production and Non-Production Environments
CCM-IVS-06
Segmentation and Segregation
CCM-IVS-07
Migration to Cloud Environments
CCM-IVS-08
Network Architecture Documentation
CCM-IVS-09
Network Defense
CCM-LOG-01
Logging and Monitoring Policy and Procedures
CCM-LOG-02
Audit Logs Protection
CCM-LOG-04
Audit Logs Access and Accountability
CCM-LOG-05
Audit Logs Monitoring and Response
CCM-LOG-06
Clock Synchronization
CCM-LOG-07
Logging Scope
CCM-LOG-08
Log Records
CCM-LOG-09
Log Protection
CCM-LOG-10
Encryption Monitoring and Reporting
CCM-LOG-11
Transaction/Activity Logging
CCM-LOG-12
Access Control Logs
CCM-LOG-13
Failures and Anomalies Reporting
CCM-SEF-01
Security Incident Management Policy and Procedures
CCM-SEF-02
Service Management Policy and Procedures
CCM-SEF-04
Incident Response Testing
CCM-SEF-05
Incident Response Metrics
CCM-SEF-06
Event Triage Processes
CCM-SEF-07
Security Breach Notification
CCM-SEF-08
Points of Contact Maintenance
CCM-STA-01
SSRM Policy and Procedures
CCM-STA-02
SSRM Supply Chain
CCM-STA-03
SSRM Guidance
CCM-STA-04
SSRM Control Ownership
CCM-STA-05
SSRM Documentation Review
CCM-STA-06
SSRM Control Implementation
CCM-STA-07
Supply Chain Inventory
CCM-STA-09
Primary Service and Contractual Agreement
CCM-STA-10
Supply Chain Agreement Review
CCM-STA-11
Internal Compliance Testing
CCM-STA-12
Supply Chain Service Agreement Compliance
CCM-STA-13
Supply Chain Governance Review
CCM-STA-14
Supply Chain Data Security Assessment
CCM-TVM-02
Malware Protection Policy and Procedures
CCM-TVM-04
Detection Updates
CCM-TVM-05
External Library Vulnerabilities
CCM-TVM-06
Penetration Testing
CCM-TVM-07
Vulnerability Identification
CCM-TVM-08
Vulnerability Prioritization
CCM-TVM-09
Vulnerability Management Reporting
CCM-TVM-10
Vulnerability Management Metrics
CCM-UEM-01
Endpoint Devices Policy and Procedures
CCM-UEM-02
Application and Service Approval
CCM-UEM-03
Compatibility
CCM-UEM-04
Endpoint Inventory
CCM-UEM-05
Endpoint Management
CCM-UEM-06
Automatic Lock Screen
CCM-UEM-07
Operating Systems
CCM-UEM-08
Storage Encryption
CCM-UEM-09
Anti-Malware Detection and Prevention
CCM-UEM-10
Software Firewall
CCM-UEM-11
Data Loss Prevention
CCM-UEM-12
Remote Locate
CCM-UEM-13
Remote Wipe
CCM-UEM-14
Third-Party Endpoint Security Posture
Show the 23 you already have
CCM-A&A-01
Audit and Assurance Policy and Procedures
CCM-AIS-01
Application and Interface Security Policy and Procedures
CCM-AIS-04
Secure Application Design and Development
CCM-AIS-05
Automated Application Security Testing
CCM-AIS-06
Automated Secure Application Deployment
CCM-BCR-01
Business Continuity Management Policy and Procedures
CCM-CCC-01
Change Management Policy and Procedures
CCM-CCC-04
Unauthorized Change Protection
CCM-CCC-06
Change Management Baseline
CCM-CEK-03
Data Encryption
CCM-GRC-01
Governance Program Policy and Procedures
CCM-GRC-05
Information Security Program
CCM-GRC-07
Information System Regulatory Mapping
CCM-IAM-01
Identity and Access Management Policy and Procedures
CCM-IAM-05
Least Privilege
CCM-IVS-03
Network Security
CCM-IVS-04
OS Hardening and Base Controls
CCM-LOG-03
Security Monitoring and Alerting
CCM-SEF-03
Incident Response Plans
CCM-STA-08
Supply Chain Risk Management
CCM-TVM-03
Vulnerability Remediation Schedule
CCM-AIS-07
Application Vulnerability Remediation
CCM-TVM-01
Threat and Vulnerability Management Policy and Procedures

How this is calculated

Already covered means a mapping runs from a control in CNCF Security Technical Advisory Group (TAG) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition