CCAK

 View Only
  • 1.  CCAK study guide

    Posted Jul 08, 2021 03:22:00 AM
    Hi,

    Reading through teh study guide I got a little lost so hoping someone can explain something to me.
    Pages 221 -224 , the figures and text show coloums "Gap", "Gap Analysis" ,"Compensating controls" etc... question where do these coloums come from? Are these manually created by the user of teh CCM and manually filled as well? If they should be there already and there is some sort of automatic analysis done, can someone explain this please?

    Reading the "Methodology  for the Mapping of the CCM" didn't help me understand this either.

    Thanks in advance
    Kevin​​

    ------------------------------
    Kevin Stander
    ------------------------------


  • 2.  RE: CCAK study guide

    CSA Instructor
    Posted Jul 10, 2021 11:59:00 PM
    Hi Kevin,
    The columns mentioned are part of the work that is being done when mapping different frameworks to CCM controls. The contributors of CCM are creating those during the  mapping process . If you download the latest CCM from CSA website, there is a "Scope applicability" tab in the spreadsheet where you can see the gaps for ISO27K mapping to CCM.

    ------------------------------
    Moshe Ferber
    ------------------------------



  • 3.  RE: CCAK study guide

    Posted Jul 11, 2021 12:33:00 AM
    Thanks Moshe,

    Looks like we have a mashup of V3.0.1 and V4 then in those pages.
    Fig3.16 shows its for CCM v3.0.1 and not new Ver 4, as well as the various links on the pages, but at the same time have included txt to Ver 4, which as you indicated is still work in progress.

    /Kevin