Security Questionnaire Mapper
Clause text

CSA Cloud Controls Matrix v4.0.1: the clauses the register cites

The 14 CSA Cloud Controls Matrix v4.0.1 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.

The text of this standard is not held in full here, so it is not quoted: each requirement carries a one-line statement of what it asks for, with its code and title, and the standard itself holds the wording.

14 clauses

the families they anchor
CSA CCM BCR-04 Business Continuity Planning

What it asks for, in one line (the standard's own text is not quoted here):

Write a business continuity plan that implements the chosen resilience strategies, and keep it approved, communicated and maintained.

Evidence an assessor expects: The current business continuity plan with version and approval; Traceability from the plan back to the chosen strategies; Distribution records showing plan holders have the current version; Maintenance record showing the plan was updated after change
Where answers usually fall short: Plan holders carrying superseded versions; Plan contents not traceable to any strategy or impact analysis
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM BCR-06 Business Continuity Exercises

What it asks for, in one line (the standard's own text is not quoted here):

Run a live exercise of the continuity and resilience plans every year, repeat it whenever something significant changes, and feed what the exercise exposes back into the plans.

Evidence an assessor expects: Exercise plans and reports from the last twelve months; Scenario and scope covered by each exercise; Post-exercise findings with owners and closure evidence; Records of exercises triggered by significant change
Where answers usually fall short: Walkthrough discussions recorded as exercises without anything being tested; Findings raised at each exercise and never closed before the next
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM BCR-08 Backup

What it asks for, in one line (the standard's own text is not quoted here):

Back up cloud-held data on a defined cycle, protect the confidentiality and integrity of the backups, and prove by restore testing that the data can actually be recovered.

Evidence an assessor expects: Backup schedules and job success records; Backup encryption and access control configuration; Restore test results with date, scope and outcome; Retention settings matched to the recovery point objective
Where answers usually fall short: Backups running successfully but never restore tested; Backups readable by the same credentials that could destroy production
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM CEK-03 Data Encryption

What it asks for, in one line (the standard's own text is not quoted here):

Apply cryptographic protection to stored data and to data moving across networks, using libraries that hold certification against an approved standard.

Evidence an assessor expects: Configuration evidence showing encryption enabled at rest and in transit per system; The certification of the cryptographic libraries or modules in use, such as a validation certificate; Inventory of data stores and transport paths with their encryption status; Exceptions where encryption is not applied and the risk acceptance behind them
Where answers usually fall short: Encryption at rest claimed from a provider default without verification per data store; Uncertified or self-built cryptographic implementations in use
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM DSP-11 Personal Data Access, Reversal, Rectification and Deletion

What it asks for, in one line (the standard's own text is not quoted here):

Give data subjects a working route to request access to, correction of or deletion of their personal data, and fulfil those requests as applicable law requires.

Evidence an assessor expects: The published request route and the procedure behind it; A log of requests received with dates and outcomes; Evidence requests were fulfilled inside the legal timeframe; The technical means by which data is located, changed or deleted across systems
Where answers usually fall short: Request route published with no process behind it; Deletion performed in the primary system while backups and exports retain the data
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM DSP-13 Personal Data Sub-processing

What it asks for, in one line (the standard's own text is not quoted here):

Control how personal data is passed to and processed by sub-processors in the service supply chain, in line with applicable law.

Evidence an assessor expects: The sub-processor register with the data each one handles; Contractual terms binding sub-processors to the required protections; Due diligence records before engagement; Evaluation or audit of sub-processor practice
Where answers usually fall short: Sub-processors engaged by delivery teams without the register being updated; Contracts silent on data protection obligations
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM DSP-16 Data Retention and Deletion

What it asks for, in one line (the standard's own text is not quoted here):

Manage data retention, archiving and deletion against business requirements and applicable law, so data is neither kept longer nor destroyed sooner than allowed.

Evidence an assessor expects: The retention schedule by data type with the requirement behind each period; Evidence retention periods are enforced technically; Deletion records at end of retention; Legal hold procedure and its interaction with deletion
Where answers usually fall short: Retention schedule published with no technical enforcement; Data retained indefinitely because deletion was never built
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM DSP-19 Data Location

What it asks for, in one line (the standard's own text is not quoted here):

Record the physical locations where data is held, processed and backed up, and be able to produce that record.

Evidence an assessor expects: The data location record covering processing, storage and backup sites; The method that keeps it current as infrastructure changes; Evidence it is available to customers or regulators who may ask; Coverage of sub-processor locations
Where answers usually fall short: Locations recorded for primary storage with backup and replica locations omitted; Record based on contracted regions rather than actual deployment
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM HRS-01 Background Screening Policy and Procedures

What it asks for, in one line (the standard's own text is not quoted here):

Keep approved background verification procedures for all new employees, contractors and third parties, scaled to the data they will access, the business requirement and accepted risk, and consistent with local law. Review at least annually.

Evidence an assessor expects: The background screening procedure with the scaling criteria; Screening records for recent hires, contractors and third party staff; Evidence of legal constraints considered per jurisdiction; Annual review record
Where answers usually fall short: Contractors and third party staff excluded from screening; One screening depth applied regardless of data access
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM IAM-02 Strong Password Policy and Procedures

What it asks for, in one line (the standard's own text is not quoted here):

Keep an approved password policy that sets strength requirements, implement it in the systems it governs, and review it at least annually.

Evidence an assessor expects: The approved password policy with its strength requirements; Technical configuration enforcing the policy per system; Annual review record; Exception records where a system cannot enforce the policy
Where answers usually fall short: Policy strength requirements not enforceable in some systems and no exception recorded; Policy stated in words with no configuration evidence
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM IAM-14 Strong Authentication

What it asks for, in one line (the standard's own text is not quoted here):

Authenticate access to systems, applications and data, using multifactor authentication at minimum for privileged users and sensitive data, and digital certificates or equivalent strength for system identities.

Evidence an assessor expects: Authentication configuration per system showing the factors required; Evidence multifactor authentication covers all privileged users and sensitive data access; The mechanism used for system identity authentication; Exception records where multifactor authentication is not applied
Where answers usually fall short: Multifactor authentication enforced at the perimeter but bypassable by direct application access; Service and system identities authenticating with static shared secrets
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM SEF-03 Incident Response Plans

What it asks for, in one line (the standard's own text is not quoted here):

Maintain an approved security incident response plan that names the internal departments, affected cloud customers and business-critical relationships such as the supply chain that may be drawn in.

Evidence an assessor expects: The approved incident response plan with its version; The stakeholder set named in the plan, internal and external; Evidence customers and supply chain relationships are addressed; Distribution records for the current version
Where answers usually fall short: Plan names internal teams only, leaving customer and supplier involvement undefined; Superseded versions still in circulation
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM SEF-07 Security Breach Notification

What it asks for, in one line (the standard's own text is not quoted here):

Notify affected parties of security breaches, including breaches reaching the organisation through its supply chain, within the timeframes set by service agreements, law and regulation.

Evidence an assessor expects: The breach notification procedure with the timeframes from each obligation; The obligations register showing notification requirements per jurisdiction and contract; Notification records for actual breaches with timestamps; Evidence supply chain breaches are captured and assessed for notification
Where answers usually fall short: Regulatory timeframes documented while contractual ones are not; Supplier breach not treated as a notifiable event for the organisation's own customers
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM TVM-03 Vulnerability Remediation Schedule

What it asks for, in one line (the standard's own text is not quoted here):

Have defined routes for both scheduled and emergency response to a discovered vulnerability, chosen according to the risk that vulnerability carries.

Evidence an assessor expects: The documented scheduled and emergency response paths with their trigger criteria; Records of emergency responses invoked and the outcome; The risk criteria that select between the two paths; Evaluation evidence that the paths work under pressure
Where answers usually fall short: Emergency path undefined, so urgent vulnerabilities queue behind routine work; Trigger criteria absent, making the choice of path arbitrary
Source: CSA Cloud Controls Matrix v4.0.1