Hi everyone, please find below the minutes from our recent workshop session.
Agenda Items (AIs)
- Progress status of the comparison review of the two versions of the TSC 2017 mapping (CCM WG and Audrey Katcher/AICPA group versions)
- Progress status of the CCMv4.0 - CISv8.0 mapping exercise and call for participation
- AoB
Participants (12):
Troin Artis
Angell Duran
Yogesh Gupta
Joel John
Erik Johnson
Bala Kaundinya
Joe Martella
Claus Matzke
Giovanni Massard
Johan Olivier
Lefteris Skoutaris (PM)
Veer
Meeting Minutes (MMs)
1. Progress status of the comparison review of the two versions of the TSC 2017 mapping (CCM WG and Audrey Katcher/AICPA group versions)
- 6 domains (AIS, CEK, DSP, GRC, HRS and IPY) have been reviewed by the group based on the feedback provide by Audrey and are close to be finalized (waiting for final validation check from Audrey),
- 3 domains are making good progress (BCR, IAM, LOG)
- Wait for reviewers for the remaining 8 domains.
- Giovanni and Troin were interested in contributing to BCR and LOG. PM gave an introduction to the mapping & gap analysis approach that is followed by the group.
- Professionals are kindly asked to consult the 'status comments' column for any pending actions on their end (AP1).
CCMv4.0 - TSC 2017 Mapping (comparison review with AICPA's version)
2. Progress status of the CCMv4.0 - CISv8.0 mapping exercise and call for participation
- David, Joel, Troin, Joe and Bala offered to contribute to the corresponding domain mappings,
- Professionals that signed up for the 1st review are kindly invited to being their review at the assigned domains (AP2),
- Missing reviewers for conducting the 1st review on CCC and IPY (please contact PM if interested in contributing),
- Deadline for 1st review is set on April 19th (second review and inputs consolidation to follow).
CCMv4.0 - CISv8.0 Mapping
3. AoB
- Next CCMv4 workshop call is scheduled on March 25th, 6 pm EEST (9 am PST/ 5 pm CET/ 12 pm EST).
Action Points (APs)
AP1: Professionals are kindly asked to consult the 'status comments' column for any pending actions on their end.
AP2: Professionals that signed up for the 1st review are kindly invited to being their review at the assigned domains.
Please let me know if anything important is missed above.Thank you all for your attendance and support.Best regards,------------------------------
Eleftherios Skoutaris
Program Manager
Cloud Security Alliance
------------------------------