The Inner Circle

 View Only
  • 1.  CCPA and GDPR in the CCM/CAIQ

    Posted May 06, 2020 07:16:00 AM
    Hello all,

    Do any of you know if there are plans to revise the CCM/CAIQ to account for the various controls required by CCPA and GDPR? 

    It would be helpful to clarify how these regulations map into existing CCM controls (or new controls).  They important points to consider, especially when evaluating a SaaS provider, and I'd conject these kind of regulations will be around for many years to come.

    If there is a direction you can point me for further discussion, please feel free.

    ------------------------------
    James Leone
    Abbott Labs
    ------------------------------


  • 2.  RE: CCPA and GDPR in the CCM/CAIQ

    Posted May 06, 2020 09:42:00 AM
    Edited by Lefteris Skoutaris May 06, 2020 09:43:17 AM
    Hello James,
                        CSA has published the PLA Code of Conduct V3 that is designed to meet the mandatory EU legal personal data protection requirements (GDPR), and to provide guidance for legal compliance and transparency on the level of data protection offered by the cloud service providers. For more information please look here: https://cloudsecurityalliance.org/privacy/gdpr/code-of-conduct/.

    The PLA WG is tasked to perform a mapping & gap analysis exercise between the PLA CoC and the CCPA. This exercise is currently ongoing.

    On a side note, the new versions CCMv4 and CAIQv4 will include privacy controls designed through the lens of security (e.g., privacy by design/default, protection of personal data/PII), but not at the level of depth required by the GDPR.

    Let me know if you have more questions.

    Best,


    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------



  • 3.  RE: CCPA and GDPR in the CCM/CAIQ

    Posted May 06, 2020 02:26:00 PM
    Eleftherios,

    Is there a target date for CCMv4?

    ------------------------------
    James Leone
    Manager
    Abbott
    ------------------------------



  • 4.  RE: CCPA and GDPR in the CCM/CAIQ

    Posted May 07, 2020 12:38:00 AM
    Hi James,
                   Yes, it is expected by end of Q4 2020 (could introduce some little delay up to early Q1 2021 due to the Covid situation).

    Best,

    Lefteris


    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------