Skip to content
Sentinel Unity
Cloud assurance

CSA Cloud Controls Matrix v4

Built as a mapping document from the start, the CCM is the framework that proves the library approach: its controls come with cross-references to other standards, and Sentinel Unity holds those references as graded mappings rather than a column in a spreadsheet.

Published by the Cloud Security Alliance for cloud service customers and providers, and widely used to assess providers during due diligence.

  • PaymentsDomain
    • Card acquiringCapability3 risks2 policies
      • Merchant settlementService4 controls2 assets
        • Daily reconciliationProcess1 risk2 controls1 finding

Every level links out to risks, controls, policies, findings, assessments, and assets

17

Control domains

Graded

Mapping to other standards

Shared

Customer / provider responsibility

0 to 5

Maturity scored

Control domains

A sample of the domains, and what carries them

The full matrix imports with its domains as domains and its controls beneath. These are the ones a cloud programme evidences most often.

Identity & Access Management

Provisioning, privileged access and review, evidenced by permission bundles and access reviews.

  • Provisioning
  • Privileged access
  • Review

Data Security & Privacy Lifecycle

Classification, retention and disposal, which is the document and asset classification model.

  • Classification
  • Retention
  • Disposal

Security Incident Management

Incident handling and forensics, recorded as findings with evidence and loss events.

  • Handling
  • Forensics
  • Notification

Supply Chain Management

Provider assessment and sub-processor visibility, which is the third-party and fourth-party register.

  • Provider assessment
  • Fourth parties
  • Contracts

Threat & Vulnerability Management

Vulnerability identification and remediation SLAs, fed by the cyber risk catalogue.

  • Vulnerabilities
  • Remediation SLA
  • Penetration testing

Governance, Risk & Compliance

Policy, risk assessment and audit planning, which is the platform itself.

  • Policy
  • Risk assessment
  • Assurance

Platform mapping

A mapping framework in a mapping library

Cross-references as graded mappings

The CCM's own references to ISO/IEC 27001, NIST SP 800-53 and PCI DSS are recorded per control with a mapping level, so partial coverage reads as partial.

Shared responsibility on the control

Whether a control is the provider's, the customer's or shared is recorded, so a customer assessment does not test what the provider owns.

Provider due diligence

Cloud providers are third parties: tiered, sent the questionnaire the tier demands, and monitored on a cadence with fourth-party exposure aggregated.

Cloud assets in the inventory

Hosting model, environment and data classification are configurable options on every asset, so cloud scope is a filter.

One evidence set

Evidence gathered for a CCM control is cited by the ISO/IEC 27001 and PCI DSS controls it maps to, not re-collected.

Findings and remediation

Gaps raise findings with owners, activities and dependencies, tracked to closure in the same queue as every other programme.

Maturity

How maturity is scored

Every CCM control is scored on the platform's six-level scale, each level carrying a written descriptor so a score means the same thing in two different business units.

Level 0

Not Performed

The practice does not happen. Recorded as an explicit level rather than a blank.

Level 1

Performed Informally

It happens, but it depends on individuals and is neither planned nor tracked.

Level 2

Planned & Tracked

Planned, resourced, and monitored, though practice still varies between teams.

Level 3

Well Defined

A defined standard process, applied consistently across the organisation.

Level 4

Quantitatively Controlled

Measured against targets, with deviation detected from the measurements themselves.

Level 5

Continuously Improving

Improvement is fed by the measurements, changing the process rather than the reporting.

Assess cloud providers and your own cloud estate on one control set

Book a walkthrough with our GRC specialists and see the platform run against the frameworks you are held to.

No commitment required. A typical demo runs 45 minutes.