17 control domains (CCM v4)
A&A โ Audit & Assurance
Audit planning, independence, management, results communication.
AIS โ Application & Interface Security
Application security policies, baseline requirements, secure deployment, secure design.
BCR โ Business Continuity Management & Operational Resilience
BC strategy, plans, testing, communication, recovery.
CCC โ Change Control & Configuration Management
Change management, configuration management baselines, change quality testing.
CEK โ Cryptography, Encryption & Key Management
Cryptographic policies, encryption standards, key management.
DSP โ Data Security & Privacy Lifecycle Management
Data classification, ownership, processing, retention, disposal.
DCS โ Datacenter Security
Off-site facility access control, environmental controls.
GRC โ Governance, Risk & Compliance
Governance framework, risk management, compliance management.
HRS โ Human Resources
Background checks, employment terms, training, exit procedures.
IAM โ Identity & Access Management
Authentication, authorization, account management, privileged access.
IPY โ Interoperability & Portability
API documentation, data portability, cloud-to-cloud interoperability.
IVS โ Infrastructure & Virtualization Security
Network security, segmentation, virtualization security, OS hardening.
LOG โ Logging & Monitoring
Log generation, retention, integrity, monitoring, alerting.
SEF โ Security Incident Management, E-Discovery & Cloud Forensics
Incident response, e-discovery, forensics, evidence handling.
STA โ Supply Chain Management, Transparency & Accountability
Supplier risk assessment, supplier security, third-party audit, governance.
TVM โ Threat & Vulnerability Management
Vulnerability identification, anti-malware, threat intelligence, vulnerability disclosure.
UEM โ Universal Endpoint Management
Endpoint security, BYOD, MDM.
CAIQ โ Consensus Assessments Initiative Questionnaire
Standardized questionnaire derived from CCM. Cloud customers ask cloud providers; cloud providers complete + publish to STAR registry.
Each control domain has questions. Cloud provider responses:
- "Yes" โ control implemented.
- "No" โ not implemented.
- "N/A" โ not applicable.
- Plus explanation.
STAR Registry levels
Level 1 STAR Self-Assessment
Cloud provider submits completed CAIQ. Free public registry entry. Limited assurance value (self-attested).
Level 2 STAR Certification
Independent third-party assessment combining ISO 27001 + CCM. Assessor certifies. Higher assurance.
Level 2 STAR Attestation
Independent third-party attestation combining SOC 2 + CCM. Higher assurance.
Level 2 STAR C-STAR
China-specific variant.
Level 3 STAR Continuous
Continuous monitoring + reporting. Limited adoption.
Cross-framework mappings
CCM published mappings to:
- ISO 27001 / 27002 / 27017 / 27018 / 27036 / 27040
- NIST CSF
- NIST SP 800-53
- PCI DSS
- HIPAA
- HITRUST CSF
- AICPA SOC 2 TSC
- GDPR
- Singapore MAS Outsourcing Guidelines
- Multiple others
Maps enable cloud customers to use CCM as cross-framework lens.
Cloud provider STAR usage
Major cloud providers:
- AWS โ STAR Level 1 + Level 2 STAR Certification.
- Microsoft Azure โ STAR Level 1 + Level 2.
- Google Cloud Platform โ STAR Level 1 + Level 2.
- Salesforce โ STAR Level 1 + Level 2.
- Many SaaS providers โ STAR Level 1.
Customer due diligence: download CAIQ from STAR registry.
SRE and AI-agent fit notes
For cloud vendor due diligence:
- CAIQ retrieval from STAR.
- Control-by-control review against own requirements.
- Mapping to org's primary framework (ISO 27001, NIST CSF).
For AI vendor due diligence:
- Major AI vendors increasingly submit STAR.
- Anthropic, OpenAI compliance posture documentation overlaps with CCM coverage.
Stefan-context implementation sketch
- For cloud / AI vendor evaluation: STAR + CAIQ as standardized due-diligence source.
- For client engagements: support client-side cloud vendor assessment.
See also
- cluster MOC ยท CSA CCM Controversies
- ISO 27001 Family and Sector Variants (ISO 27017 cloud-specific)