CSA CCM v4.1 - control domain coverage
securityv1/01 Views
/02 About
Seventeen independent cloud assurance domains mapped to a protected workload; designed for ownership and evidence scoping, not compliance scoring.
Purpose: visualize the current Cloud Security Alliance CCM v4.1 domain structure as a cloud security architecture coverage model. The seventeen nodes are control-domain groupings only. The complete CCM v4.1 includes 197 control objectives and must be consulted directly. Use the three views to assign owners, identify which business services and technical assets are affected, then map individual approved controls, assessments, responsibility assignments and evidence in the receiving workspace. Source: https://cloudsecurityalliance.org/research/cloud-controls-matrix. Original Arq graph and layout; not an official CSA diagram, CCM dataset copy, certification, completed assessment, or endorsement.
Published by Lattix · 18 elements · 17 relationships · validated on publish
/03 Contents
- Application
- Cloud service workload
- Control
- A&A - Audit and Assurance, AIS - Application and Interface Security, BCR - Business Continuity Management and Operational Resilience, CCC - Change Control and Configuration Management, CEK - Cryptography, Encryption and Key Management, DCS - Datacenter Security, DSP - Data Security and Privacy, GRC - Governance, Risk Management and Compliance, HRS - Human Resources Security, IAM - Identity and Access Management, IPY - Interoperability and Portability, IVS - Infrastructure and Virtualization Security, LOG - Logging and Monitoring, SEF - Security Incident Management, E-Discovery and Cloud Forensics, STA - Supply Chain Management, Transparency and Accountability, TVM - Threat and Vulnerability Management, UEM - Universal Endpoint Management