CSA Cloud Controls Matrix Cluster
Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM). Cloud-specific control framework. Maps to multiple frameworks (ISO 27001, NIST CSF, PCI DSS, HIPAA, others). STAR Registry for cloud-provider attestation.
Anchors
Provenance
- Cloud Security Alliance — founded 2008. Non-profit cloud-security industry association.
- CCM v1 (2010).
- CCM v3.0 / v3.0.1 (2013-2017).
- CCM v4 (2021).
- Continuous evolution.
What CCM is
Cloud-specific control framework. ~200 controls across 17 control domains. Designed for:
- Cloud customer evaluation of providers.
- Cloud provider security implementation.
- Mapping to other frameworks (ISO 27001 / 27017, NIST, PCI, HIPAA).
Control domains (CCM v4)
- Audit & Assurance (A&A)
- Application & Interface Security (AIS)
- Business Continuity Management & Operational Resilience (BCR)
- Change Control & Configuration Management (CCC)
- Cryptography, Encryption & Key Management (CEK)
- Data Security & Privacy Lifecycle Management (DSP)
- Datacenter Security (DCS)
- Governance, Risk & Compliance (GRC)
- Human Resources (HRS)
- Identity & Access Management (IAM)
- Interoperability & Portability (IPY)
- Infrastructure & Virtualization Security (IVS)
- Logging & Monitoring (LOG)
- Security Incident Management, E-Discovery & Cloud Forensics (SEF)
- Supply Chain Management, Transparency & Accountability (STA)
- Threat & Vulnerability Management (TVM)
- Universal Endpoint Management (UEM)
Detail in CSA CCM Control Domains.
STAR Registry
Cloud Security Alliance Security, Trust, Assurance and Risk (STAR) Registry. Three levels:
- Level 1 STAR Self-Assessment: cloud providers submit completed CAIQ (Consensus Assessments Initiative Questionnaire — based on CCM) for public registry.
- Level 2 STAR Certification: third-party assessment by approved auditor. ISO 27001 + CCM combined.
- Level 2 STAR Attestation: SOC 2 + CCM combined.
- Level 2 STAR C-STAR: China-specific.
Why this matters
- Cloud provider evaluation: major cloud providers (AWS, Azure, GCP, others) submit STAR.
- Cross-framework mapping: cloud customers can use CCM to map cloud provider posture to their own framework (ISO 27001, etc.).
- CAIQ questionnaire: common cloud vendor due-diligence input.
Related clusters
See also
CSA CCM Cluster (pillars MOC) · position · anchors · ISO 27001 Cluster · SOC 2 Cluster