Identity & Access Management
Provisioning, privileged access and review, evidenced by permission bundles and access reviews.
- Provisioning
- Privileged access
- Review
Built as a mapping document from the start, the CCM is the framework that proves the library approach: its controls come with cross-references to other standards, and Sentinel Unity holds those references as graded mappings rather than a column in a spreadsheet.
Published by the Cloud Security Alliance for cloud service customers and providers, and widely used to assess providers during due diligence.
Every level links out to risks, controls, policies, findings, assessments, and assets
17
Control domains
Graded
Mapping to other standards
Shared
Customer / provider responsibility
0 to 5
Maturity scored
Control domains
The full matrix imports with its domains as domains and its controls beneath. These are the ones a cloud programme evidences most often.
Provisioning, privileged access and review, evidenced by permission bundles and access reviews.
Classification, retention and disposal, which is the document and asset classification model.
Incident handling and forensics, recorded as findings with evidence and loss events.
Provider assessment and sub-processor visibility, which is the third-party and fourth-party register.
Vulnerability identification and remediation SLAs, fed by the cyber risk catalogue.
Policy, risk assessment and audit planning, which is the platform itself.
Platform mapping
The CCM's own references to ISO/IEC 27001, NIST SP 800-53 and PCI DSS are recorded per control with a mapping level, so partial coverage reads as partial.
Whether a control is the provider's, the customer's or shared is recorded, so a customer assessment does not test what the provider owns.
Cloud providers are third parties: tiered, sent the questionnaire the tier demands, and monitored on a cadence with fourth-party exposure aggregated.
Hosting model, environment and data classification are configurable options on every asset, so cloud scope is a filter.
Evidence gathered for a CCM control is cited by the ISO/IEC 27001 and PCI DSS controls it maps to, not re-collected.
Gaps raise findings with owners, activities and dependencies, tracked to closure in the same queue as every other programme.
Maturity
Every CCM control is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.
Level 0
Not Performed
The practice does not happen. Recorded as an explicit level rather than a blank.
Level 1
Performed Informally
It happens, but it depends on individuals and is neither planned nor tracked.
Level 2
Planned & Tracked
Planned, resourced, and monitored, though practice still varies between teams.
Level 3
Well Defined
A defined standard process, applied consistently across the organisation.
Level 4
Quantitatively Controlled
Measured against targets, with deviation detected from the measurements themselves.
Level 5
Continuously Improving
Improvement is fed by the measurements, changing the process rather than the reporting.
Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.
No commitment required. A typical demo runs 45 minutes.