Cloud Controls Matrix

Expand all | Collapse all

Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

  • 1.  Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

    Posted Dec 14, 2023 05:19:00 AM
    Edited by Lefteris Skoutaris Dec 14, 2023 05:19:59 AM

    Dear members,

    CCM WG and leadership is interested in pursuing a mapping of CCM V4 to the NIST CSF v2.0 Draft.

     Introduction:
    This new mapping project involves a mapping and gap analysis and it is expected to kick-off during the CCM WG call next Wednesday, Dec. 20th.

    This mapping project follows a previous collaboration that CSA had with NIST with the mapping of CCM to CSF v1.1., that resulted in useful feedback to NIST of cloud security deltas to be included in CSF v2.0. The CCM - NIST CSF v1.1 mapping is published within the current version of CCM V4.0. (see Scope Applicability (Mappings) tab).

    The objective of the project is the requirements comparison of the two frameworks. In this way an opportunity is provided for cloud organizations to identify the equivalent (overlapping) security requirements between the two, and more importantly the missing (deltas) cloud-specific CCM V4 security requirements in NIST CSF V2, especially when seeking to integrate these with their cloud security and compliance programs.

    In this respect, CSA, and under the umbrella of the CCM WG, would like to put together a team of experts, who have good experience in the implementation/assessment of NIST CSF and/or CCMv4 framework's security controls.

    While the CSF v2.0 is not yet at a final version, it is expected that there are not going to be any major changes introduced until its release in early 2024.

      CCM WG meetings cadence:
      CCM WG has 2 call sessions, one is weekly, the other biweekly. Experts are needed to attend at least our biweekly calls to align to the CCM WG mapping methodology and touch base on progress.

      Project duration:
      The overall project duration is expected to be approx. 3-4 months.

      Should you be interested in participating in the project, please reply back to this thread or message my inbox. Please also consider joining our next week's call.

      Feel free to reach out in case you have any questions.

      Best regards,

      ------------------------------
      Lefteris Skoutaris
      Cloud Controls Matrix, Program Manager
      Cloud Security Alliance
      ------------------------------



    • 2.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 14, 2023 05:27:00 AM

      Hi Lefteris

      I have fully recovered from the effects of my brain stroke and I am back to normal life. It did take some time but now I am raring for action. Please send me invites to this mapping.

      Looking forward to contribute.

      Regards

      Agni



      ------------------------------
      Agnidipta Sarkar
      Evangelist EMERITUS
      ------------------------------



    • 3.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 15, 2023 12:27:00 AM

      Hey Agni,

      Long time no see, it is great to know that you are doing well and have recovered!

      It is a pleasure having you back with us in the WG.

      With regards to the project's kick-off let me know if you can participate in next week's call. If not, let me know to find a workaround to properly onboard you.

      Looking forward to working together.



      ------------------------------
      [Lefteris] [Skoutaris]
      [Cloud Controls Matrix, Program Manager]
      [Cloud Security Alliance]
      ------------------------------



    • 4.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 15, 2023 11:25:00 PM

      Hi Lefteris,

      Please add me to the list as a reviewer.

      I may not be able to join meeting on 20th Dec since I already have a workshop, but planning to attend meetings in January for this mapping activity.

      Thank you.
      Suranjit



      ------------------------------
      Suranjit Paul CISSP, CCSP, CCSK
      ------------------------------



    • 5.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 18, 2023 12:44:00 AM
      Interested.

      Elastos Chimwanda | CIA | CISA | CISSP | CCSP | ISO/IEC 27001 LA
      Independent Consultant
      Internal Audit | IT Audit | InfoSec | CloudSec
      Mobile: +263772998112
      Email: [email protected]





    • 6.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 18, 2023 07:24:00 AM

      Hi Lefteris,

      I am interested. It would be great working with Agni!

      Thanks,

      Deb



      ------------------------------
      Deb Mukherjee, CISSP, CCSK, GCP, CBCP
      Associate Director - Cloud Risk Compliance
      RBC
      Toronto, Canada
      ------------------------------



    • 7.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 19, 2023 07:24:00 AM
      Lefteris,

      Long time no talk to! I am in a place where I can assist and participate again so I would love to start back being involved and I'm happy to work on this project. Please add me.

      Thanks,
      Dr. Angela





    • 8.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 20, 2023 08:44:00 PM
      Lefteris,

      I am interested. can I still participate?

      BOLAJI BANKOLE

      PECB Certified Trainer
      CEH, CPETM, CCSPTM, CSSMBBTM, CSSBBTM, CSSGBTM, CSSYBTM,
      PECB Senior Lead Cyber Security Manager
      PECB Lead Cyber Security Manager,
      PECB Lead Cyber Security Manager trainer,
      PECB Lead Auditor,
      PECB Lead Auditor Trainer,
      MCSA, MCSE, MCITP, MCTS
      +2347035654727 | [email protected] | www.pecb.com

      Important: Check the authenticity of the stated information here
      CERTIFIED TRAINER






    • 9.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 20, 2023 08:47:00 AM

      Hey Lefteris, count me in, please.

      Cheers,

      Marcin



      ------------------------------
      Marcin Masłowski CISA
      SecOps Manager
      Brainly
      ------------------------------



    • 10.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 21, 2023 07:25:00 AM

      Hi Lefteris, 

        Cound me in.

      Leo Magallon, CISSP, CISA



      ------------------------------
      Leo Magallon
      Senior Security Consultant
      Set Solutions, Inc.
      ------------------------------



    • 11.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 21, 2023 09:56:00 AM

      Please count me in . Please send the working meeting invite to [email protected]



      ------------------------------
      Hema Lakkaraju
      Unknown
      SAS
      ------------------------------



    • 12.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 22, 2023 01:55:00 AM

      Hi Lefteris

      Please count me in, looking to contribute.

      Kind Regards



      ------------------------------
      Ira Goel
      Gira Group B.V.
      Gira Group B.V.
      ------------------------------



    • 13.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 22, 2023 05:49:00 AM

      Hi Lefteris, Please have me included in the working group - [email protected] 

      Regards,

      Lokesh 



      ------------------------------
      Lokesh Balu
      Senior Principal Enigineer
      Dell
      ------------------------------



    • 14.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Dec 29, 2023 06:22:00 AM

      Hi, Lefteris!

      I will be interested to contribute.

      My mail is [email protected]

      Best regard

      Staffan



      ------------------------------
      Staffan Huslid
      Security Advisor
      Truesec
      ------------------------------



    • 15.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Jan 01, 2024 07:25:00 AM

      Hello and Good Evening Lefteris,

      If the opportunity is still available, I would be interested!!

      Regards,

      Nilesh Roy | +919820094678 | [email protected]



      ------------------------------
      Nilesh Roy Vice President - Technology at SM Networks & S
      Vice President - Technology
      SM Networks and Solutions Pvt. Ltd.
      Mumbai
      ------------------------------



    • 16.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Jan 11, 2024 09:12:00 AM

      Thank you all for your interest.
      Please consider joining the CCM WG calls to discuss further the means of your contribution to the project, or other CCM WG activities.
      The mapping has kicked-off and it is in progress.



      ------------------------------
      [Lefteris] [Skoutaris]
      [Cloud Controls Matrix, Program Manager]
      [Cloud Security Alliance]
      ------------------------------



    • 17.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Jan 12, 2024 07:20:00 AM

      Thanks for the info @Lefteris Skoutaris .   I found a Cloud Controls Matrix group that appears to be a private community and a CCM User Group.   I am a member of the CCM User Group.  Is that the right group?



      ------------------------------
      Leo Magallon
      Regional Principal Security Consultant
      Trace3
      ------------------------------



    • 18.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Jan 12, 2024 07:22:00 AM

      Hi - I am interested to participate in this. I have been doing mapping / cross walks over 7 years.



      ------------------------------
      Hema Lakkaraju
      Unknown
      SAS
      ------------------------------



    • 19.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Jan 12, 2024 07:24:00 AM

      Alright, I think I found the right group.   For all others that were looking for the group link here it is:   https://circle.cloudsecurityalliance.org/engage/volunteer/volunteeropportunities/volunteer-opportunity-details?VolunteerOpportunityKey=5a2f0ef0-f09c-4d5b-92d7-d217bbcdac9b&CommunityKey=c5e9ef65-7674-441f-add0-9143d32f88b1



      ------------------------------
      Leo Magallon
      Senior Security Consultant
      Set Solutions, Inc.
      ------------------------------



    • 20.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Feb 29, 2024 08:59:00 PM

      Hi Lefteris, I am definitely interested.



      ------------------------------
      T. Devon Artis
      Cloud Security Architect/DevSecOps Lead
      ------------------------------



    • 21.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Mar 04, 2024 06:04:00 AM

      I am definitely interested. FYI I help craft the first release of CSF.



      ------------------------------
      Z. Anna Johnston
      ------------------------------



    • 22.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Mar 04, 2024 06:10:00 AM

      Thank you all for your interest in this project.
      It's been a while since the initial post and the mapping is in very good progress.
      I will reach out to you in case any additional support is needed.
      In the meantime, please stay tuned for other project announcements, as there are a few coming up.
      Looking forward to meeting you in our calls.



      ------------------------------
      [Lefteris] [Skoutaris]
      [Cloud Controls Matrix, Program Manager]
      [Cloud Security Alliance]
      ------------------------------



    • 23.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Mar 05, 2024 07:11:00 AM

      I am interested



      ------------------------------
      Jorge Ivan Marmolejo Cardona
      Advisor 27001 and GRDP
      QWERTY GRC
      ------------------------------



    • 24.  RE: Mapping the CCM V4 to Draft NIST CSF v2.0. - Call for Participation

      Posted Mar 04, 2024 07:02:00 AM
      Hi 

      i am interested .