7% of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 you already have
ISO 27043 already covers about 7% of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, leaving
184 of 197 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 184
No control in ISO 27043
maps directly to one in Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO 27043 reaches these. This is the list to scope.
CCM-A&A-01Audit and Assurance Policy and Procedures
CCM-A&A-02Independent Assessments
CCM-A&A-03Risk Based Planning Assessment
CCM-A&A-04Requirements Compliance
CCM-A&A-05Audit Management Process
CCM-AIS-01Application and Interface Security Policy and Procedures
CCM-AIS-02Application Security Baseline Requirements
CCM-AIS-03Application Security Metrics
CCM-AIS-04Secure Application Design and Development
CCM-AIS-05Automated Application Security Testing
CCM-AIS-06Automated Secure Application Deployment
CCM-AIS-07Application Vulnerability Remediation
CCM-BCR-01Business Continuity Management Policy and Procedures
CCM-BCR-02Risk Assessment and Impact Analysis
CCM-BCR-03Business Continuity Strategy
CCM-BCR-04Business Continuity Planning
CCM-BCR-06Business Continuity Exercises
CCM-BCR-09Disaster Response Plan
CCM-BCR-10Response Plan Exercise
CCM-BCR-11Equipment Redundancy
CCM-CCC-01Change Management Policy and Procedures
CCM-CCC-02Quality Testing
CCM-CCC-03Change Management Technology
CCM-CCC-04Unauthorized Change Protection
CCM-CCC-05Change Agreements
CCM-CCC-06Change Management Baseline
CCM-CCC-07Detection of Baseline Deviation
CCM-CCC-08Exception Management
CCM-CCC-09Change Restoration
CCM-CEK-02CEK Roles and Responsibilities
CCM-CEK-03Data Encryption
CCM-CEK-04Encryption Algorithm
CCM-CEK-05Encryption Change Management
CCM-CEK-06Encryption Change Cost Benefit Analysis
CCM-CEK-07Encryption Risk Management
CCM-CEK-08CSC Key Management Capability
CCM-CEK-09Encryption and Key Management Audit
CCM-CEK-14Key Destruction
CCM-CEK-17Key Deactivation
CCM-CEK-21Key Inventory Management
CCM-DCS-01Off-Site Equipment Disposal Policy and Procedures
CCM-DCS-02Off-Site Transfer Authorization Policy and Procedures
CCM-DCS-03Secure Area Policy and Procedures
CCM-DCS-04Secure Media Transportation Policy and Procedures
CCM-DCS-05Assets Classification
CCM-DCS-06Assets Cataloguing and Tracking
CCM-DCS-07Controlled Access Points
CCM-DCS-08Equipment Identification
CCM-DCS-09Secure Area Authorization
CCM-DCS-10Surveillance System
CCM-DCS-11Unauthorized Access Response Training
CCM-DCS-12Cabling Security
CCM-DCS-13Environmental Systems
CCM-DCS-14Secure Utilities
CCM-DCS-15Equipment Location
CCM-DSP-01Security and Privacy Policy and Procedures
CCM-DSP-02Secure Disposal
CCM-DSP-05Data Flow Documentation
CCM-DSP-06Data Ownership and Stewardship
CCM-DSP-07Data Protection by Design and Default
CCM-DSP-08Data Privacy by Design and Default
CCM-DSP-09Data Protection Impact Assessment
CCM-DSP-10Sensitive Data Transfer
CCM-DSP-11Personal Data Access, Reversal, Rectification and Deletion
CCM-DSP-12Limitation of Purpose in Personal Data Processing
CCM-DSP-13Personal Data Sub-processing
CCM-DSP-14Disclosure of Data Sub-processors
CCM-DSP-15Limitation of Production Data Use
CCM-DSP-16Data Retention and Deletion
CCM-DSP-17Sensitive Data Protection
CCM-DSP-18Disclosure Notification
CCM-GRC-01Governance Program Policy and Procedures
CCM-GRC-02Risk Management Program
CCM-GRC-03Organizational Policy Reviews
CCM-GRC-04Policy Exception Process
CCM-GRC-05Information Security Program
CCM-GRC-06Governance Responsibility Model
CCM-GRC-07Information System Regulatory Mapping
CCM-HRS-01Background Screening Policy and Procedures
CCM-HRS-02Acceptable Use of Technology Policy and Procedures
CCM-HRS-03Clean Desk Policy and Procedures
CCM-HRS-04Remote and Home Working Policy and Procedures
CCM-HRS-06Employment Termination
CCM-HRS-07Employment Agreement Process
CCM-HRS-08Employment Agreement Content
CCM-HRS-09Personnel Roles and Responsibilities
CCM-HRS-11Security Awareness Training
CCM-HRS-12Personal and Sensitive Data Awareness and Training
CCM-HRS-13Compliance User Responsibility
CCM-IAM-01Identity and Access Management Policy and Procedures
CCM-IAM-02Strong Password Policy and Procedures
CCM-IAM-03Identity Inventory
CCM-IAM-04Separation of Duties
CCM-IAM-07User Access Changes and Revocation
CCM-IAM-09Segregation of Privileged Access Roles
CCM-IAM-10Management of Privileged Access Roles
CCM-IAM-11CSCs Approval for Agreed Privileged Access Roles
CCM-IAM-12Safeguard Logs Integrity
CCM-IAM-13Uniquely Identifiable Users
CCM-IAM-14Strong Authentication
CCM-IAM-15Passwords Management
CCM-IAM-16Authorization Mechanisms
CCM-IPY-01Interoperability and Portability Policy and Procedures
CCM-IPY-02Application Interface Availability
CCM-IPY-03Secure Interoperability and Portability Management
CCM-IPY-04Data Portability Contractual Obligations
CCM-IVS-01Infrastructure and Virtualization Security Policy and Procedures
CCM-IVS-02Capacity and Resource Planning
CCM-IVS-04OS Hardening and Base Controls
CCM-IVS-05Production and Non-Production Environments
CCM-IVS-06Segmentation and Segregation
CCM-IVS-07Migration to Cloud Environments
CCM-IVS-08Network Architecture Documentation
CCM-IVS-09Network Defense
CCM-LOG-02Audit Logs Protection
CCM-LOG-03Security Monitoring and Alerting
CCM-LOG-04Audit Logs Access and Accountability
CCM-LOG-05Audit Logs Monitoring and Response
CCM-LOG-06Clock Synchronization
CCM-LOG-10Encryption Monitoring and Reporting
CCM-LOG-11Transaction/Activity Logging
CCM-LOG-13Failures and Anomalies Reporting
CCM-SEF-01Security Incident Management Policy and Procedures
CCM-SEF-02Service Management Policy and Procedures
CCM-SEF-03Incident Response Plans
CCM-SEF-04Incident Response Testing
CCM-SEF-05Incident Response Metrics
CCM-SEF-06Event Triage Processes
CCM-SEF-07Security Breach Notification
CCM-SEF-08Points of Contact Maintenance
CCM-STA-01SSRM Policy and Procedures
CCM-STA-02SSRM Supply Chain
CCM-STA-04SSRM Control Ownership
CCM-STA-05SSRM Documentation Review
CCM-STA-06SSRM Control Implementation
CCM-STA-07Supply Chain Inventory
CCM-STA-08Supply Chain Risk Management
CCM-STA-09Primary Service and Contractual Agreement
CCM-STA-10Supply Chain Agreement Review
CCM-STA-11Internal Compliance Testing
CCM-STA-12Supply Chain Service Agreement Compliance
CCM-STA-13Supply Chain Governance Review
CCM-STA-14Supply Chain Data Security Assessment
CCM-TVM-01Threat and Vulnerability Management Policy and Procedures
CCM-TVM-02Malware Protection Policy and Procedures
CCM-TVM-03Vulnerability Remediation Schedule
CCM-TVM-04Detection Updates
CCM-TVM-05External Library Vulnerabilities
CCM-TVM-07Vulnerability Identification
CCM-TVM-08Vulnerability Prioritization
CCM-TVM-09Vulnerability Management Reporting
CCM-TVM-10Vulnerability Management Metrics
CCM-UEM-01Endpoint Devices Policy and Procedures
CCM-UEM-02Application and Service Approval
CCM-UEM-04Endpoint Inventory
CCM-UEM-05Endpoint Management
CCM-UEM-06Automatic Lock Screen
CCM-UEM-07Operating Systems
CCM-UEM-08Storage Encryption
CCM-UEM-09Anti-Malware Detection and Prevention
CCM-UEM-10Software Firewall
CCM-UEM-11Data Loss Prevention
CCM-UEM-14Third-Party Endpoint Security Posture
Show the 13 you already have
CCM-CEK-01Encryption and Key Management Policy and Procedures
CCM-DSP-04Data Classification
CCM-GRC-08Special Interest Groups
CCM-HRS-10Non-Disclosure Agreements
CCM-IAM-05Least Privilege
CCM-IAM-06User Access Provisioning
CCM-IAM-08User Access Review
CCM-IVS-03Network Security
CCM-LOG-01Logging and Monitoring Policy and Procedures
CCM-LOG-12Access Control Logs
CCM-TVM-06Penetration Testing
How this is calculated
Already covered means a mapping runs from a control in ISO 27043 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition