ChaptersEventsBlog
How is your enterprise using AI Agents? Help us benchmark security and take the survey before November 30 →

Download Publication

CCM and CAIQ FAQ
CCM and CAIQ FAQ

CCM and CAIQ FAQ

Release Date: 04/05/2023

Working Group: Cloud Controls Matrix

The Cloud Controls Matrix (CCM) is a framework of controls (policies and procedures) that are essential for cloud computing security. It is created and updated by CSA and aligned to CSA best practices. The controls in CCM cover all key aspects of cloud technology and can be used to assess and guide the security of any cloud implementation. CSA has arranged CCM’s controls in both spreadsheet and machine-readable versions of yes/no questions that are easy to read and use, known as the Consensus Assessment Initiative Questionnaire (CAIQ). 

Learn more about what CCM and CAIQ are, why they’re important, and how to use them.
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
Introductory Guidance to AICM
Introductory Guidance to AICM
AICM Implementation & Auditing Guidelines (Frameworks)
AICM Implementation & Auditing Guidelines (Fram...
Code of Practice for Assessment Firms Offering STAR
Code of Practice for Assessment Firms Offering ...
Implementing CCM: Threat & Vulnerability Management Controls
Implementing CCM: Threat & Vulnerability Management Controls
Published: 11/21/2025
It’s Time to Make Cloud Threat Modeling Continuous
It’s Time to Make Cloud Threat Modeling Continuous
Published: 11/20/2025
Understanding STAR for AI Level 2: A Practical Step Toward AI Security Compliance
Understanding STAR for AI Level 2: A Practical Step Toward AI Secur...
Published: 11/19/2025
VDI, DaaS, or Local Secure Enclaves? A CCM‑Aligned Playbook for BYOD in 2025
VDI, DaaS, or Local Secure Enclaves? A CCM‑Aligned Playbook for BYO...
Published: 11/04/2025

Interested in helping develop research with CSA?

Related Certificates & Training