Cloud Controls Matrix

Expand all | Collapse all

CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

  • 1.  CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 11, 2022 07:16:00 AM
    Edited by Lefteris Skoutaris Apr 12, 2022 12:18:12 AM
    Dear members,
    CSA and the CCM WG would like to embark on a new project that involves a mapping and gap analysis between the CCM v4.0 and the new version of ISO/IEC 27002:2022, recently published.

    As you might already know CSA's STAR program and STAR level 2 Certification combines the best of two worlds, ISO/IEC 27001:2013 and CCMv4.0. Organizations that wish to migrate to the cloud are able to build cloud security requirements on top of ISO27001 and meet also compliance to CCM.

    The objective of the project is the requirements comparison of the 2 frameworks. In this way an opportunity is provided for organizations to identify the equivalent security requirements between the two, and more importantly the missing cloud-specific CCM security requirements in ISO/IEC 27001/02, especially when seeking to integrating these with their cloud security and compliance programs.

    In this respect, CSA, and under the umbrella of the CCM WG, would like to put together a team of experts, who have good experience in the implementation/assessment of ISO27001/02 and/or CCMv4 security controls.  Should you be interested in participating in the project, please contact me and I will walk you through the on-boarding process and mapping methodology.

    Best regards,






    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------


  • 2.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 13, 2022 12:18:00 PM
    Hello Eleftherios, 
    Am interested in participating in the mapping of CCMv4.0 and ISO27001/2

    ------------------------------
    David Don
    Executive Council
    IIM Africa
    ------------------------------



  • 3.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 15, 2022 12:13:00 PM
    Hello Eleftherios,

    I am also interested in participating in the mapping and gap analysis between the CCM v4.0 and the new version of ISO/IEC 27002:2022, recently published.

    Thanks!

    Lou Tinto


    ------------------------------
    Lou Tinto
    Sr. Security
    City Electric Supply
    ------------------------------



  • 4.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 15, 2022 12:13:00 PM
    Good day, I would like to be part of this project effort, as a contributor or reviewer for my region

    ------------------------------
    Frank Chin Hai
    Chief
    iTGRC Asia
    ------------------------------



  • 5.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 19, 2022 12:44:00 AM
    Edited by 현호 장 Apr 19, 2022 12:45:18 AM
    Hello Eleftherios, 

    I am also interested in participating in the mapping and gap analysis between the CCM v4.0 and ISO/IEC 27002:2022

    Thanks!

    ------------------------------
    Hyunho Chang
    Research Manager
    Tatum Security
    ------------------------------




  • 6.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 19, 2022 01:02:00 AM

    Hi there, I am interested in this comparison, I implemented information security Configuration compliance capability for my organization based on CIS benchmark, vendor best practices and company security requirements. 

    Thanks
    Hema



    ------------------------------
    Hema Bhatt
    Project Delivery Lead
    ANZ
    ------------------------------



  • 7.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 20, 2022 07:42:00 AM
    Good Afternoon Eleftherios,

    I would be very interested in joining this working group please.

    Best Regards

    James


    ------------------------------
    James Turrell
    Security
    n/a
    ------------------------------



  • 8.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 25, 2022 10:57:00 AM
    Hi - I'd like to contribute too. Look forward to further comms.

    Kind regards
    Mohin

    ------------------------------
    Mohin G
    Consultant
    Independent
    ------------------------------



  • 9.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 25, 2022 12:50:00 PM
    I would like to participate. I just need to be sent an updated meeting invite so that I can put it on my calendar.

    Thanks,
    Angela





  • 10.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 26, 2022 08:30:00 AM
    I would like to participate in this effort.

    --Ron Palladino

    ------------------------------
    Ron Palladino
    Security Risk& Awareness Program Manager
    IEEE
    ------------------------------



  • 11.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 26, 2022 08:30:00 AM
    Hi Eleftherios, 

    I'd like to contribute, thanks.

    Alex.


    ------------------------------
    Alex Stezycki
    Security Consultant
    Capgemini
    ------------------------------



  • 12.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 27, 2022 07:46:00 AM
    Hi Alex

    Please include me. Keen to contribute.

    Regards
    Krishna.
    AWS, Azure x 4 Solutions architect expert, Cissp, cisa


    ------------------------------
    Krishna das Manghat
    Associate Dir
    kpmg
    ------------------------------



  • 13.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted Apr 27, 2022 10:54:00 AM
    Hi, I'd like join the team.
    Due to TZ constraints, I will contribute mainly through document base.
    -

    ------------------------------
    Koichiro Watanabe
    Solution Architect
    Microsoft Corp.
    ISO/IEC JTC1 SC27 WG1/WG4 expert
    Japan
    ------------------------------



  • 14.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted May 02, 2022 07:31:00 AM
    I am interested as a volunteer.

    ------------------------------
    tuhin goswami
    Consultant
    Digital14
    ------------------------------



  • 15.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted May 03, 2022 09:19:00 AM
    Yes I am interested 





  • 16.  RE: CCMv4.0 - ISO/IEC 27001/02:2022 Mapping (Call for participation)

    Posted May 03, 2022 08:03:00 PM
    Hi Eleftherios - interested in collaborating.

    ------------------------------
    Miguel Angel Arenas CISM, CRISC, ITIL
    Cybersecurity Governance PM
    Alphacredit
    Mexico City
    ------------------------------