Download Publication

CCM v4.0 Addendum - ECUC PP v2.1
Release Date: 02/12/2024
Working Group: Cloud Controls Matrix
This document is an addendum to the 'ECUC Position Paper v2.1 (ECUC PP v2.1) that contains controls mapping between the CSA CCM v4.0 and the ECUC PPv2.1. The document aims to help ECUC PPv2.1 compliant organizations meet CCM v4.0 requirements. This is achieved by identifying compliance gaps in ECUC PPv2.1 in relation to the CCM v4.0. This document contains the following information:
• Controls Mapping
• Gap Identification (i.e. Partial, Full or No Gap)
• Gap Analysis
The document is structured as follows. The tab 'CCMv4.0 - ECUC PPv2.1' contains the mappings as well as associated information such as the gap analysis and compensating controls. In this tab, columns:
• A-D contain the CCMv4.0 domains and control specifications.
• E-H contain the results of the mapping and gap analysis exercise.
The "Terminology" tab provides a list of terms used in this document and their definitions.
The CSA and the CCM working group hope that organizations will find this document useful for their cloud security compliance programs.
The contents of this document could contain technical inaccuracies, typographical errors and out-of-date information.
• Controls Mapping
• Gap Identification (i.e. Partial, Full or No Gap)
• Gap Analysis
The document is structured as follows. The tab 'CCMv4.0 - ECUC PPv2.1' contains the mappings as well as associated information such as the gap analysis and compensating controls. In this tab, columns:
• A-D contain the CCMv4.0 domains and control specifications.
• E-H contain the results of the mapping and gap analysis exercise.
The "Terminology" tab provides a list of terms used in this document and their definitions.
The CSA and the CCM working group hope that organizations will find this document useful for their cloud security compliance programs.
The contents of this document could contain technical inaccuracies, typographical errors and out-of-date information.
Download this Resource
Related Resources
Interested in helping develop research with CSA?
Related Certificates & Training
.png)
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more
Learn more

.jpeg)

.jpeg)