The Cloud Security Alliance released their latest version of the Cloud Control Matrix (CCM) on 1/20/21. It is available from their website after answering a few questions. The mappings to Scope Applicability, Architectural Relevance, Corporate Governance Relevance, Cloud Service Delivery Model Applicability, Supplier Relationship, are not yet available, but the CSA has released the matrix to assist organizations to prepare to upgrade to version 4.
Following are the changes reported on the website:
Changes in version 4:
- Ensured coverage of requirements deriving from new cloud technologies.
- New controls and security responsibility matrix, improved auditability of the controls, and enhanced interoperability and compatibility with other standards.
- Changes in structure of the framework with a new domain dedicated to Log and Monitoring (LOG), and modifications in the existing ones (GRC, A&A, UEM, CEK).
Sign up on the site to receive updates when the mappings are available.