The Inner Circle

 View Only
Expand all | Collapse all

SSRM Project Announcement - Call for Participation

Anonymous Member

Anonymous MemberJan 04, 2023 02:23:00 PM

Anonymous Member

Anonymous MemberJan 04, 2023 02:33:00 PM

Anonymous Member

Anonymous MemberJan 04, 2023 02:35:00 PM

Anonymous Member

Anonymous MemberJan 04, 2023 02:21:00 PM

Anonymous Member

Anonymous MemberJan 04, 2023 02:08:00 PM

Anonymous Member

Anonymous MemberJan 05, 2023 07:06:00 AM

Anonymous Member

Anonymous MemberJan 06, 2023 11:06:00 AM

Anonymous Member

Anonymous MemberJan 06, 2023 11:06:00 AM

Anonymous Member

Anonymous MemberJan 06, 2023 11:08:00 AM

  • 1.  SSRM Project Announcement - Call for Participation

    Posted Dec 06, 2022 05:13:00 AM
    Edited by Lefteris Skoutaris May 29, 2023 07:34:55 AM

    Dear Members,

    CSA and the CCM WG are interested to kick-off a new project for developing guidelines that pertain to the Shared Security Responsibility Model (SSRM) and that are to be tailored to each of the total of 197 CCMv4 control specifications.

    Introduction
    The Shared Security Responsibility Model (SSRM) is inherent to the use of cloud services. It is essential that cloud service customers (CSCs) are fluent in, and up to date on, how they and their cloud service providers (CSPs) share the responsibility for securing their cloud footprint. 

    The Cloud Controls Matrix (CCM) and existing framework of its underlying components are already SSRM-enhanced and aid CSPs and CSCs delineate their part of controls ownership and implementation responsibility. Nevertheless, a complete SSRM guidance for all controls in the CCMv4 is currently missing.


    Objective

    The objective of the project is to extend the CCMv4 framework by developing additional guidelines that pertain to the Shared Security Responsibility Model in order to educate cloud customers and help them better understand their security responsibilities within the shared cloud infrastructure. 


    AWS Support

    The project will be supervised by the WG co-chairs and is to be further evaluated & enhanced by AWS, who represents the project from the standpoint of the Cloud Service Provider.  In that direction, CCM WG co-chair David Nickles (AWS) is working to provide the CCM WG with AWS input.

    Timeline

    Project is expected to kick-off on December 15th and be completed end of Q4 2023, according to the established 2022-2023 project plan & timeline.


    Industry practitioners, cloud security experts, who have a good understanding & experience on the SSRM (especially from cloud controls' implementation standpoint) and are interested in participating & contributing to this project, are kindly invited to contact me.

    Note: For convenience, please consider adding your email address to your reply so that I directly invite you to our SSRM call sessions.

    Best regards,



    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------



  • 2.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 07, 2022 11:35:00 AM
    I'd be glad to assist.

    ------------------------------
    mar sten
    dell
    dell
    ------------------------------



  • 3.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 04, 2023 02:32:00 PM
    This post was removed


  • 4.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 06, 2023 06:47:00 AM
    I like to be part of your project.

    Email: [email protected]

    Thanks for the opportunity

    ------------------------------
    Tariq Khan
    CEO
    ANM Transformational Solutions
    ------------------------------



  • 5.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 08, 2022 06:51:00 AM
    I would also like to participate.

    I am currently involved with developing cloud-native security-hardened DevSecOps architecture and creating risk management strategies.

    ------------------------------
    Joseph Young
    CEO
    Young Security, Inc.
    ------------------------------



  • 6.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 08, 2022 07:55:00 AM
    Eleftherios.

    Count me in. This is directly on point with much of my work. I co-chair two working groups for CSA and contribute to others. The cross-fertilization would be great.

    Cheers,
    alex.

    ------------------------------
    Alex Sharpe
    Principal
    Sharpe42
    [email protected]
    Co-Chair Philosophy & Guiding Principles Working Group
    Co-Chair Organizational Strategy & Governance Working Group
    ------------------------------



  • 7.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 09, 2022 02:15:00 AM
    Hi Marvin, Joseph, Alex, et. al.,
    Thank you for your interest in this very important CSA project, you are most welcome!

    Please join us at the next CCM WG meeting, Thursday, Dec 15th (all CCM WG meetings' call info can be found at the CCM WG channel and under the 'Events' tab)
    In that call we are going to kick-off the project (and discuss project/meetings cadence, SSRM worksheet structure, share and refine charter, etc.). 

    Looking forward to having you in the call with us.

    Thanks,
    Lefteris

    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------



  • 8.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 12, 2022 08:12:00 AM
    I would like to assist. 

    Thanks

    Shamik

    ------------------------------
    Shamik Kacker
    Director
    Dell Technology
    ------------------------------



  • 9.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 04, 2023 02:23:00 PM
    This post was removed


  • 10.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 12, 2022 01:47:00 PM
    Thank you, @Lefteris Skoutaris. Thursday, I will be with a family member undergoing an outpatient procedure. Worse case, I will be listening in.

    Cheers,
    alex.
    ​​

    ------------------------------
    Alex Sharpe
    Principal
    Sharpe42
    [email protected]
    Co-Chair Philosophy & Guiding Principles Working Group
    Co-Chair Organizational Strategy & Governance Working Group
    ------------------------------



  • 11.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 23, 2022 08:34:00 AM
    Hi Eleftherios,

    I would like to assist in this effort, if there is still room.


    ------------------------------
    Dwarkesh Dhabalia
    Cybersecurity Manager
    Ernst & Young
    ------------------------------



  • 12.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 04, 2023 02:33:00 PM
    This post was removed


  • 13.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 27, 2022 05:46:00 AM
    Hi Eleftherios, if you are still looking for support happy to do so.

    ------------------------------
    Saan Vandendriessche CISM | CCSP | CISSP | CRISC | ISO 27001 LI
    Brussels - Belgium
    ------------------------------



  • 14.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 04, 2023 02:35:00 PM
    This post was removed


  • 15.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 03, 2023 05:45:00 AM
    Eleftherios,

    Happy Holidays!

    I'd like to participate, helping to support the initiative, including extending with additional guidelines, and operationalizing results - integrating into the Global Cyber First Responder (training/certification) initiative we are leading for public and private critical infrastructure (CI) protection, working with DHS, federal agencies, state/local agencies, tribal, territorial, National White Collar Crime Center (NW3C), Fusion Centers, and critical infrastructure sector organizations and experts.  Cyber response roles, responsibilities and competencies from a proactive and reactive perspective, and alignment of physical/cyber/cyber-physical response protocols.  

    Beginning the first of the year, DHS will be developing a supporting Security Resilience Table-Top Exercise working with DHS Physical and Cyber Exercise Divisions .  Scenario - Physical, Cyber, Cyber-Physical including Cognitive Security injects (Disinformation, Misinformation, Malign Influence).  

    Needless to say, shared cloud infrastructure and security responsibilities need to be incorporated into Cyber First Responder competencies, roles and responsibilities and the supporting exercise,, and vice-versa, Cyber First Responder responsibilities integrated into  the CCMv4 framework.

    I look forward to discussing in greater detail and learning how I can assist to support the SSRM.  Exciting 2023! 


    ------------------------------
    Deborah Kobza
    President/EO
    International Association of Certified ISAOs (IACI)
    ------------------------------



  • 16.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 04, 2023 02:21:00 PM
    This post was removed


  • 17.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 03, 2023 05:46:00 AM
    Hi Eleftherios,

    If there is still room, I would be very interested in contributing. 

    Thanks
    Chandra


    ------------------------------
    Chandra Rajagopalan
    ------------------------------



  • 18.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 04, 2023 02:08:00 PM
    This post was removed


  • 19.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 03, 2023 08:00:00 AM
    Hi Eleftherios - Let me know if you're still looking for participants.

    Murray Rosenthal, CISA, CRISC
    Managing Consultant
    TELUS Communications Inc.
    Toronto, Ontario, CANADA
    [email protected]

    ------------------------------
    Murray Rosenthal
    Managing Consultant
    TELUS Corporation
    ------------------------------



  • 20.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 03, 2023 08:17:00 AM
    Lefteris, hello
    Happy New year!

    Put me down as a resource for this project.

    Thanks

    ------------------------------
    JOHN DIMARIA
    ME
    CSA
    [email protected]
    ------------------------------



  • 21.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 05, 2023 05:58:00 AM
    Hi, Eleftherios!

    I'd like to participate in this project if there are still slots available; thank you!

    ------------------------------
    Kyle Reidell
    Security Engineering
    Amazon Web Services
    ------------------------------



  • 22.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 05, 2023 07:06:00 AM
    This post was removed


  • 23.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 06, 2023 06:47:00 AM
    Hi Eleftherios,

    I want to assist in this effort if the participation is still open..


    ------------------------------
    Ashwani Parashar
    Versa Networks
    Versa Networks
    ------------------------------



  • 24.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 06, 2023 06:52:00 AM
    Hi Eleftherios,

    I'm available if project still on...

    Kind regards


    ------------------------------
    Tariq Khan
    Freelance
    Auditor, Advisor & Trainer
    ------------------------------



  • 25.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 06, 2023 11:06:00 AM
    This post was removed


  • 26.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 06, 2023 11:06:00 AM
    This post was removed


  • 27.  RE: SSRM Project Announcement - Call for Participation

    This message was posted by a user wishing to remain anonymous
    Posted Jan 06, 2023 11:08:00 AM
    This post was removed


  • 28.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 09, 2023 06:00:00 AM
    Hi Eric and Eleftherios,

     I am interested in volunteering, if this is still open.

    Thank you!

    ------------------------------
    Duronke Owoleso MBA, CISSP, CISA, CDPSE, PMP
    Mississauga ON
    ------------------------------



  • 29.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 09, 2023 02:28:00 PM
    Hi Erik,

    My email address is [email protected]

    Thank you,

    Duronke

    ------------------------------
    Duronke Owoleso MBA, CISSP, CISA, CDPSE, PMP
    [email protected]
    ------------------------------



  • 30.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 09, 2023 06:00:00 AM
    hi Eleftherios
    would like to participate if still possible. 


    ------------------------------
    Rami Mans
    Executive Manager, Cloud & Emerging Technology
    Westpac
    ------------------------------



  • 31.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 09, 2023 07:16:00 AM
    Hi Eleftherios, 

    I am interested. Please send me more detail on my mail id - [email protected]

    Regards, 
    Ankit Sharma

    ------------------------------
    Ankit Sharma
    Security Advocate
    Cisco Systems
    ------------------------------



  • 32.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 10, 2023 11:43:00 AM
    I will love to participate in this project

    [email protected]

    Thanks

    ------------------------------
    YUSUF OWOLABI OLATUNDE
    Lecturer
    Summit University, Offa
    ------------------------------



  • 33.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 12, 2023 11:38:00 AM
    Hi Eleftherios

    Id be happy to get involved if there is still space

    thanks

    Ryan

    ------------------------------
    Ryan M Green
    RMG Cyber Consulting Ltd
    RMG Cyber Consulting Ltd
    ------------------------------



  • 34.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 13, 2023 07:13:00 AM
    Hi Eleftherios,

    I will love to participate in this project if the slot is still open.

    [email protected]

    Best,
    Akshay Bhardwaj
    <quillbot-extension-portal></quillbot-extension-portal>

    ------------------------------
    Akshay Bhardwaj
    Sr. InfoSec Associate
    Sprinklr
    ------------------------------



  • 35.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 13, 2023 10:25:00 AM
    I would like to be involved on this, if possible.

    ------------------------------
    John Paul Espina
    Vice-President
    Societe Generale
    ------------------------------



  • 36.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 17, 2023 07:23:00 AM
    Greetings:  I will be happy to help if a spot is still available.  Thank you

    ------------------------------
    Sarita Garg
    Consultant
    Independent
    ------------------------------



  • 37.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 17, 2023 07:24:00 AM
    If still accepting participants, please consider adding me.

    Blessen Varghese
    [email protected]

    ------------------------------
    Blessen Varghese
    Security Architect
    BLP
    ------------------------------



  • 38.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 17, 2023 07:24:00 AM
    I would like to be involved.

    Brian LeeVan
    Principal Security Consultant
    Verizon Business
    [email protected]

    ------------------------------
    Brian LeeVan
    Principal Security Consultant
    Verizon
    ------------------------------



  • 39.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 17, 2023 08:11:00 AM
    Thank you all for your interest in the SSRM project.
    Project is currently at an early phase and ongoing.
    Your participation is very welcome.


    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------



  • 40.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 18, 2023 08:31:00 AM
    Edited by Aristotelis Gkortsilas Jan 18, 2023 09:09:20 AM


  • 41.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 18, 2023 08:31:00 AM
    Edited by Aristotelis Gkortsilas Jan 18, 2023 09:09:55 AM
    Hi Eleftherios,

    I would also like to participate and support the SSRM project.
    [email protected]

    Kind regards,
    Aristotelis

    ----------------------
    Aristotelis Gkortsilas
    Director Security Risk Governance
    ***
    ---------------------



  • 42.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 25, 2023 07:57:00 AM
    I am interested to your  SSRM Project . Please include me. My knowledge to Project and Security and Risk Management will be helpful.

    Thank you and looking forward to work in your project

    Sincerely
    Dr Md Mazharul Islam,PhD
    PMP,MPM,CIPM,CRM,CISA,CRMF
    Cloud Security Alliance 
    Administrator of
    Bangladesh Chapted

    ------------------------------
    Dr Md Mazharul Islam
    Chief Executive Officer
    Certification providers
    ------------------------------



  • 43.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 25, 2023 07:58:00 AM

    Hi Eleftherios,

    I would also like to participate and support the SSRM project.
    [email protected]

    Thanks,
    Bill



    ------------------------------
    Bill Campbell
    CEO
    Balancelogic
    ------------------------------



  • 44.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 31, 2023 04:33:00 PM
    Please contribute your knowledge to improve the SSRM Project Participation
    Sincerely,
    Dr Md Mazharul Islam,PhD
    CEO
    American Academy of Finance and Management, AAFM & AAPM BD
    Admin founder of Cloud Security Alliance 





  • 45.  RE: SSRM Project Announcement - Call for Participation

    Posted Feb 07, 2023 11:12:00 AM
    Yes, please let me know which role you are interested in to use my expertize. 





  • 46.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 25, 2023 07:57:00 AM
    Hi Eleftherios, if you are still looking for participants, I am interested.

    My email address is [email protected]

    ------------------------------
    Agnivesh Sathasivam
    Security Architect
    Bibby Financial Services
    ------------------------------



  • 47.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 27, 2023 07:05:00 AM
    Hi Eleftherios,

    I and 2 colleagues of mine would also like to participate and support the SSRM project.

    [email protected]
    [email protected]
    [email protected]

    Thank you,
    Marco

    ------------------------------
    Marco Domenichini
    Security Competence Lead
    Bip
    ------------------------------



  • 48.  RE: SSRM Project Announcement - Call for Participation

    Posted Jan 31, 2023 08:16:00 AM
    Hi Eleftherios,

    I would like to participate, contribute and support the SSRM project. 

    [email protected]


    ------------------------------
    Ziya Karakaya
    Asst. Prof. Dr.
    Atılım University
    ------------------------------



  • 49.  RE: SSRM Project Announcement - Call for Participation

    Posted Apr 10, 2023 03:18:00 AM
    Edited by Lefteris Skoutaris Apr 10, 2023 03:18:45 AM

    Dear members,
    We are looking for cloud security experts with good experience of CCM to help us develop (and at a later stage review) the SSRM Implementation Guidelines for the CCM V4.

    At the current stage of development, we are missing experts to help us determine the SSRM for the DCS, SEF and UEM domains of CCM V4. 
    • Datacenter Security (DCS) (DCS includes controls that extend beyond the 'IaaS Provider's' scope of responsibilities)
    • Security Incident Management, E-Discovery, & Cloud Forensics (SEF)

    • Universal Endpoint Management (UEM)

    CCM V4 can be accessed here.

    For more information about project's timeline and effort needed on the above works, feel free to text me directly.


    Thank you,



    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------



  • 50.  RE: SSRM Project Announcement - Call for Participation

    Posted Apr 11, 2023 08:38:00 AM

    I'm interested , let me know how can I?



    ------------------------------
    Adnan Rafique
    ATechnologies
    ATechnologies
    ------------------------------



  • 51.  RE: SSRM Project Announcement - Call for Participation

    Posted Apr 11, 2023 07:40:00 AM

    I would also like to participate.

    regards,
    David



    ------------------------------
    David souto rial
    Enterprise Security Architect
    Airbus GmbH
    ------------------------------