How about the FedRAMP (Moderate or High?) version of the NIST 800-53 controls and baseline?
Which NIST baseline did we use to determine the control set for the 800-53 V5 mapping - Low, Moderate, High?
------------------------------
Erik Johnson CCSK, CCSP, CISSP, PMP
Senior Research Analyst
Cloud Security Alliance
[email protected]------------------------------
Original Message:
Sent: May 19, 2023 06:02:36 AM
From: Eleftherios Skoutaris
Subject: To what other standard/framework CCM V4 should be mapped to?
Dear members,
Mappings are a useful tool for cloud organizations to identify the equivalent (overlapping) security requirements between CCM V4 and a target framework, and more importantly the missing cloud-specific CCM security requirements (deltas), especially when cloud organizations are seeking to integrating these missing requirements within their cloud security and compliance programs.
The CCM V4 is currently mapped with the following frameworks:
- AICPA TSC (2017)
- CCM v3.0.1
- CIS v8.0
- ISF SOGP 2022
- ISO/IEC 27001 (2013, 2022)
- ISO/IEC 27002 (2013, 2022)
- ISO/IEC 27017 (2015)
- ISO/IEC 27018 (2019)
- NIST 800-53r5
- PCI DSS v3.2.1
Mapping to NIST CSF v1.1 is completed and soon is to be published.
Mapping to PCI DSS V4 is in progress.
What are other frameworks the CCM WG should prioritize to map CCM V4 with, and more importantly, why?
------------------------------
Eleftherios Skoutaris
Program Manager
Cloud Security Alliance
------------------------------