CSA Cloud Controls Matrix v4.0.1: the clauses the register cites
The 14 CSA Cloud Controls Matrix v4.0.1 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.
The text of this standard is not held in full here, so it is not quoted: each requirement carries a one-line statement of what it asks for, with its code and title, and the standard itself holds the wording.
14 clauses
the families they anchorCSA CCM BCR-04 Business Continuity PlanningWhat it asks for, in one line (the standard's own text is not quoted here):
Write a business continuity plan that implements the chosen resilience strategies, and keep it approved, communicated and maintained.
Where answers usually fall short: Plan holders carrying superseded versions; Plan contents not traceable to any strategy or impact analysis
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM BCR-06 Business Continuity ExercisesWhat it asks for, in one line (the standard's own text is not quoted here):
Run a live exercise of the continuity and resilience plans every year, repeat it whenever something significant changes, and feed what the exercise exposes back into the plans.
Where answers usually fall short: Walkthrough discussions recorded as exercises without anything being tested; Findings raised at each exercise and never closed before the next
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM BCR-08 BackupWhat it asks for, in one line (the standard's own text is not quoted here):
Back up cloud-held data on a defined cycle, protect the confidentiality and integrity of the backups, and prove by restore testing that the data can actually be recovered.
Where answers usually fall short: Backups running successfully but never restore tested; Backups readable by the same credentials that could destroy production
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM CEK-03 Data EncryptionWhat it asks for, in one line (the standard's own text is not quoted here):
Apply cryptographic protection to stored data and to data moving across networks, using libraries that hold certification against an approved standard.
Where answers usually fall short: Encryption at rest claimed from a provider default without verification per data store; Uncertified or self-built cryptographic implementations in use
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM DSP-11 Personal Data Access, Reversal, Rectification and DeletionWhat it asks for, in one line (the standard's own text is not quoted here):
Give data subjects a working route to request access to, correction of or deletion of their personal data, and fulfil those requests as applicable law requires.
Where answers usually fall short: Request route published with no process behind it; Deletion performed in the primary system while backups and exports retain the data
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM DSP-13 Personal Data Sub-processingWhat it asks for, in one line (the standard's own text is not quoted here):
Control how personal data is passed to and processed by sub-processors in the service supply chain, in line with applicable law.
Where answers usually fall short: Sub-processors engaged by delivery teams without the register being updated; Contracts silent on data protection obligations
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM DSP-16 Data Retention and DeletionWhat it asks for, in one line (the standard's own text is not quoted here):
Manage data retention, archiving and deletion against business requirements and applicable law, so data is neither kept longer nor destroyed sooner than allowed.
Where answers usually fall short: Retention schedule published with no technical enforcement; Data retained indefinitely because deletion was never built
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM DSP-19 Data LocationWhat it asks for, in one line (the standard's own text is not quoted here):
Record the physical locations where data is held, processed and backed up, and be able to produce that record.
Where answers usually fall short: Locations recorded for primary storage with backup and replica locations omitted; Record based on contracted regions rather than actual deployment
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM HRS-01 Background Screening Policy and ProceduresWhat it asks for, in one line (the standard's own text is not quoted here):
Keep approved background verification procedures for all new employees, contractors and third parties, scaled to the data they will access, the business requirement and accepted risk, and consistent with local law. Review at least annually.
Where answers usually fall short: Contractors and third party staff excluded from screening; One screening depth applied regardless of data access
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM IAM-02 Strong Password Policy and ProceduresWhat it asks for, in one line (the standard's own text is not quoted here):
Keep an approved password policy that sets strength requirements, implement it in the systems it governs, and review it at least annually.
Where answers usually fall short: Policy strength requirements not enforceable in some systems and no exception recorded; Policy stated in words with no configuration evidence
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM IAM-14 Strong AuthenticationWhat it asks for, in one line (the standard's own text is not quoted here):
Authenticate access to systems, applications and data, using multifactor authentication at minimum for privileged users and sensitive data, and digital certificates or equivalent strength for system identities.
Where answers usually fall short: Multifactor authentication enforced at the perimeter but bypassable by direct application access; Service and system identities authenticating with static shared secrets
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM SEF-03 Incident Response PlansWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain an approved security incident response plan that names the internal departments, affected cloud customers and business-critical relationships such as the supply chain that may be drawn in.
Where answers usually fall short: Plan names internal teams only, leaving customer and supplier involvement undefined; Superseded versions still in circulation
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM SEF-07 Security Breach NotificationWhat it asks for, in one line (the standard's own text is not quoted here):
Notify affected parties of security breaches, including breaches reaching the organisation through its supply chain, within the timeframes set by service agreements, law and regulation.
Where answers usually fall short: Regulatory timeframes documented while contractual ones are not; Supplier breach not treated as a notifiable event for the organisation's own customers
Source: CSA Cloud Controls Matrix v4.0.1
CSA CCM TVM-03 Vulnerability Remediation ScheduleWhat it asks for, in one line (the standard's own text is not quoted here):
Have defined routes for both scheduled and emergency response to a discovered vulnerability, chosen according to the risk that vulnerability carries.
Where answers usually fall short: Emergency path undefined, so urgent vulnerabilities queue behind routine work; Trigger criteria absent, making the choice of path arbitrary
Source: CSA Cloud Controls Matrix v4.0.1