The Inner Circle

 View Only
  • 1.  CCM mapping to ISO 27k

    Posted Aug 07, 2020 02:11:00 AM
    ​Hi !

    I am looking for the criteria used to map the Cloud Controls to the ISO 27k controls in the CCM.

    Some of these relationships do not look obvious to me so I would like to understand the reasoning behind.

    Thanks in advance for any hints


    ------------------------------
    Diego Alvarado
    Policy Security Officer
    AXA GO
    ------------------------------


  • 2.  RE: CCM mapping to ISO 27k

    Posted Aug 10, 2020 08:20:00 AM
    @Daniele Catteddu and @Lefteris Skoutaris - Could one of you help answer this question? ​​

    ------------------------------
    Hillary Baron CCSK v4
    Program Manager, Research
    CSA
    Seattle WA
    ------------------------------



  • 3.  RE: CCM mapping to ISO 27k

    Posted Aug 11, 2020 02:54:00 AM
    Hi,

    You could forward to Diego the CCM Mapping Methodology.

    https://downloads.cloudsecurityalliance.org/assets/research/cloud-controls-matrix/ccm-mapping-methodology.pdf

    ------------------------------
    Michael Roza CPA, CISA, CIA
    ------------------------------



  • 4.  RE: CCM mapping to ISO 27k

    Posted Aug 11, 2020 07:09:00 AM
    Thanks Hillary and Michael!

    ------------------------------
    Diego Alvarado
    Policy Security Officer
    AXA GO
    ------------------------------



  • 5.  RE: CCM mapping to ISO 27k

    Posted Aug 11, 2020 07:31:00 AM
    Hi Diego,  I will do the mapping overnight for you in the CCM matrix

    Rgds
    Shane Feeney
    ISO27001 Lead Auditor, CISM, SABSA, CISP

    ------------------------------
    Shane Feeney
    Seniro Consultant
    Cemax Consulting
    ------------------------------



  • 6.  RE: CCM mapping to ISO 27k

    Posted Jul 06, 2021 07:36:00 AM
    Is this mapping available to share? I would like to have a copy of it.

    ------------------------------
    Aditya Chordia
    IT Validation & Compliance Manager
    Amerisource Bergen
    ------------------------------



  • 7.  RE: CCM mapping to ISO 27k

    Posted Jul 06, 2021 07:54:00 AM
    Hi Aditya,
    the mapping is included under the 'scope applicability' tab of the CCMv4.
    You can download the standard here.
    Lefteris

    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------