CSA CCM Control Domains

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

17 control domains (CCM v4)

A&A โ€” Audit & Assurance

Audit planning, independence, management, results communication.

AIS โ€” Application & Interface Security

Application security policies, baseline requirements, secure deployment, secure design.

BCR โ€” Business Continuity Management & Operational Resilience

BC strategy, plans, testing, communication, recovery.

CCC โ€” Change Control & Configuration Management

Change management, configuration management baselines, change quality testing.

CEK โ€” Cryptography, Encryption & Key Management

Cryptographic policies, encryption standards, key management.

DSP โ€” Data Security & Privacy Lifecycle Management

Data classification, ownership, processing, retention, disposal.

DCS โ€” Datacenter Security

Off-site facility access control, environmental controls.

GRC โ€” Governance, Risk & Compliance

Governance framework, risk management, compliance management.

HRS โ€” Human Resources

Background checks, employment terms, training, exit procedures.

IAM โ€” Identity & Access Management

Authentication, authorization, account management, privileged access.

IPY โ€” Interoperability & Portability

API documentation, data portability, cloud-to-cloud interoperability.

IVS โ€” Infrastructure & Virtualization Security

Network security, segmentation, virtualization security, OS hardening.

LOG โ€” Logging & Monitoring

Log generation, retention, integrity, monitoring, alerting.

SEF โ€” Security Incident Management, E-Discovery & Cloud Forensics

Incident response, e-discovery, forensics, evidence handling.

STA โ€” Supply Chain Management, Transparency & Accountability

Supplier risk assessment, supplier security, third-party audit, governance.

TVM โ€” Threat & Vulnerability Management

Vulnerability identification, anti-malware, threat intelligence, vulnerability disclosure.

UEM โ€” Universal Endpoint Management

Endpoint security, BYOD, MDM.

CAIQ โ€” Consensus Assessments Initiative Questionnaire

Standardized questionnaire derived from CCM. Cloud customers ask cloud providers; cloud providers complete + publish to STAR registry.

Each control domain has questions. Cloud provider responses:

  • "Yes" โ€” control implemented.
  • "No" โ€” not implemented.
  • "N/A" โ€” not applicable.
  • Plus explanation.

STAR Registry levels

Level 1 STAR Self-Assessment

Cloud provider submits completed CAIQ. Free public registry entry. Limited assurance value (self-attested).

Level 2 STAR Certification

Independent third-party assessment combining ISO 27001 + CCM. Assessor certifies. Higher assurance.

Level 2 STAR Attestation

Independent third-party attestation combining SOC 2 + CCM. Higher assurance.

Level 2 STAR C-STAR

China-specific variant.

Level 3 STAR Continuous

Continuous monitoring + reporting. Limited adoption.

Cross-framework mappings

CCM published mappings to:

  • ISO 27001 / 27002 / 27017 / 27018 / 27036 / 27040
  • NIST CSF
  • NIST SP 800-53
  • PCI DSS
  • HIPAA
  • HITRUST CSF
  • AICPA SOC 2 TSC
  • GDPR
  • Singapore MAS Outsourcing Guidelines
  • Multiple others

Maps enable cloud customers to use CCM as cross-framework lens.

Cloud provider STAR usage

Major cloud providers:

  • AWS โ€” STAR Level 1 + Level 2 STAR Certification.
  • Microsoft Azure โ€” STAR Level 1 + Level 2.
  • Google Cloud Platform โ€” STAR Level 1 + Level 2.
  • Salesforce โ€” STAR Level 1 + Level 2.
  • Many SaaS providers โ€” STAR Level 1.

Customer due diligence: download CAIQ from STAR registry.

SRE and AI-agent fit notes

For cloud vendor due diligence:

  • CAIQ retrieval from STAR.
  • Control-by-control review against own requirements.
  • Mapping to org's primary framework (ISO 27001, NIST CSF).

For AI vendor due diligence:

  • Major AI vendors increasingly submit STAR.
  • Anthropic, OpenAI compliance posture documentation overlaps with CCM coverage.

Stefan-context implementation sketch

  • For cloud / AI vendor evaluation: STAR + CAIQ as standardized due-diligence source.
  • For client engagements: support client-side cloud vendor assessment.

See also