Cloud Controls Matrix

  • 1.  SSRM Project Announcement - Call for Participation

    Posted Dec 06, 2022 05:13:00 AM
    Edited by Lefteris Skoutaris Jan 13, 2023 07:44:35 AM
    Dear Members,

    CSA and the CCM WG are interested to kick-off a new project for developing guidelines that pertain to the Shared Security Responsibility Model (SSRM) and that are to be tailored to each of the total of 197 CCMv4 control specifications.

    Introduction
    The Shared Security Responsibility Model (SSRM) is inherent to the use of cloud services. It is essential that cloud service customers (CSCs) are fluent in, and up to date on, how they and their cloud service providers (CSPs) share the responsibility for securing their cloud footprint. 

    The Cloud Controls Matrix (CCM) and existing framework of its underlying components are already SSRM-enhanced and aid CSPs and CSCs delineate their part of controls ownership and implementation responsibility. Nevertheless, a complete SSRM guidance for all controls in the CCMv4 is currently missing.


    Objective

    The objective of the project is to extend the CCMv4 framework by developing additional guidelines that pertain to the Shared Security Responsibility Model in order to educate cloud customers and help them better understand their security responsibilities within the shared cloud infrastructure. 


    AWS Support

    The project will be supervised by the WG co-chairs and is to be further evaluated & enhanced by AWS that represents the project from the standpoint of the Cloud Service Provider.  In that direction, CCM WG co-chair David Nickles (AWS) is working to provide the CCM WG with AWS input.

    Timeline

    Project is expected to kick-off on December 15th and be completed end of Q3 2023, according to the established 2022-2023 project timeline.


    Industry practitioners, cloud security experts, who have a good understanding & experience on the SSRM (especially from cloud controls' implementation standpoint) and are interested in participating & contributing to this project, are kindly invited to contact me.

    Note: For convenience, please consider adding your email address to your reply so that I directly invite you to our SSRM call sessions.

    Best regards,



    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------


  • 2.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 08, 2022 06:03:00 AM
    Hi,

    I would like to participate.

    Keith

    ------------------------------
    Keith Stocks CISSP, CISA, CISM, CIPP/US, CIPM, FIP, C/CISO
    VP, Third Party Cyber Security Transformation and Governance
    State Street Corporation
    Goodyear AZ
    ------------------------------



  • 3.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 09, 2022 01:17:00 AM
    Hi Keith, et. al.,
    Thank you for your interest in the project.
    Please consider navigating to the 'Events' tab and locate the call info for the next CCM WG meeting, Thursday, Dec 15th.
    In that call we are going to kick-off the project (and discuss project/meetings cadence, worksheet structure, share and refine charter, etc.). 

    Looking forward to seeing you in the call with us.

    Lefteris

    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------



  • 4.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 09, 2022 10:14:00 AM
    Hi Lefteris, Team,

    Hope you are doing well. 

    Keen to participate in this project. Please keep me in loop.

    Thanks
    Krishna



    ------------------------------
    Krishna M
    Head, Cloud Security, Regional lead - Cyber Defense, KPMG Australia.
    CISSP, CISA, ISO 27001 LA, AWS, Azure Security and Architecture specialisations.
    ------------------------------



  • 5.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 12, 2022 02:18:00 AM
    Hi Krishna,
    Thank you for your interest in this project.
    Would you be eager to share an email address with for future communication and sharing project related documentation?
    As mentioned in this thread, please consider joining our Thursday's kick-off call session.
    Thanks,
    Lefteris

    ------------------------------
    Eleftherios Skoutaris
    Program Manager
    Cloud Security Alliance
    ------------------------------



  • 6.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 10, 2022 07:17:00 AM
    I am looking forward to participation, and I have added the Dec 15th CCMv4 Workshop Session to my calendar.

    ------------------------------
    Joseph Young
    CEO
    Young Security, Inc.
    ------------------------------



  • 7.  RE: SSRM Project Announcement - Call for Participation

    Posted Dec 15, 2022 09:42:00 AM
    I could not attend due to severe weather and a tornado watch.

    ------------------------------
    Joseph Young
    CEO
    Young Security, Inc.
    ------------------------------