Cloud Controls Matrix

Auditing Guidelines dev. Team Call - May 28th [Meeting Minutes]

  • 1.  Auditing Guidelines dev. Team Call - May 28th [Meeting Minutes]

    Posted Jun 01, 2021 05:33:00 AM

    Hi everyone,
                        please find below a status update for the CCM AGs dev. exercise and the minutes from our recent call session.

    Relevant documentation:
    • CCMv4.0 Auditing Guidelines worksheet (Input document)
    • CCAK extract: module 7 CCM Auditing Guidelines (supportive documentation)
    • CCAK extract: CCM Audit Workbook (supportive documentation)


    Agenda Items (AIs):

    1. Touch base on the progress status of Auditing Guidelines (AGs) development
    2. AoB


    Participants (10):
    Parminder Bawa
    Madhav Chablani
    Brian Dorsey
    Angell Duran
    Sanjeev Gupta
    Jan Jacobsen
    Bilal Khattak
    Agnidipta Sarkar
    Lefteris Skoutaris (PM)
    Tanya Tipper-Luster

     

    Meeting Minutes (MMs)

    1. Touch base on the progress status of Auditing Guidelines (AGs) development
    • Auditors in the group have drafted AGs for all the CCMv4.0 domains (with AGs in BCR and CEK, IAM, STA pending 2nd review and consolidation of 2nd review comments respectively),
    • Steve has conducted the 2nd review on the AGs of domains SEF, IAM and STA,
    • Renu has consolidated Steve's input on STA and also drafted the pending AGs for STA-11 that was missing (Steve is kindly invited to review this control's AGs),
    • Claus has conducted a 2nd review on the AGs of IAM and Tanya is consolidating the received input,
    • Jan, Bilal, Damian, Steve and Sanjeev will be scheduling a meeting to discuss the 2nd review comments provided by Steve for the AGs of CEK,
    • Professionals participating in the exercise are kindly invited to consult the 'Progress Status' tab (column H) for any pending actions on their end (AP1),
    • Next steps to the AGs development will be discussed during the CCM leadership meeting on June 7th.


    Snapshot taken from 'progress status' tab of the AG workbook

    2. AoB

    • Next CCMv4.0 AG dev. call is scheduled on June 4th, 5 pm EEST (7am PST / 10am EST / 4pm CET).

    Action Points (APs)

    AP1: Professionals participating in the exercise are kindly invited to consult the 'Progress Status' tab (column H) for any pending actions on their end.


    Please let me know if anything important is missed above. 

    Thank you all for your attendance and support.
    Best regards,

    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------