# CSA Cloud Controls Matrix v4

Framework id: `csa_ccm_v4`. Cloud Controls. Publisher: Cloud Security Alliance (CSA). Version: 4.0. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://cloudsecurityalliance.org/research/cloud-controls-matrix

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (197, average coverage 78%)
- AA-01 Audit and Assurance Policy and Procedures: CA-01, CA-02, AU-01 (85%)
- AA-02 Independent Assessments: CA-02, CA-07, CA-08 (85%)
- AA-03 Risk Based Planning Assessment: CA-02, RA-03, RA-07 (80%)
- AA-04 Requirements Compliance: CA-02, CA-05, CA-09 (75%)
- AA-05 Audit Management Process: CA-02, CA-05, AU-06 (78%)
- AA-06 Remediation: CA-05, CA-02, RA-07 (85%)
- AIS-01 Application and Interface Security Policy and Procedures: SA-01, SA-08, SI-01 (80%)
- AIS-02 Application Security Baseline Requirements: SA-08, SA-11, SA-15 (78%)
- AIS-03 Application Security Metrics: SA-11, CA-07, PM-06 (65%)
- AIS-04 Secure Application Design and Development: SA-03, SA-08, SA-11, SA-15 (85%)
- AIS-05 Automated Application Security Testing: SA-11, CA-08, RA-05 (78%)
- AIS-06 Automated Secure Application Deployment: SA-03, CM-03, CM-02 (68%)
- AIS-07 Application Vulnerability Remediation: RA-05, SI-02, SA-11 (82%)
- BCR-01 Business Continuity Management Policy and Procedures: CP-01, CP-02 (85%)
- BCR-02 Risk Assessment and Impact Analysis: CP-02, RA-03, RA-09 (82%)
- BCR-03 Business Continuity Strategy: CP-02, CP-07, CP-08 (78%)
- BCR-04 Business Continuity Planning: CP-02, CP-03, CP-04 (88%)
- BCR-05 Documentation: CP-02, PL-02, PL-07 (75%)
- BCR-06 Business Continuity Exercises: CP-04, CP-03 (88%)
- BCR-07 Communication: CP-02, IR-06, CP-08 (72%)
- BCR-08 Backup: CP-09, CP-06 (88%)
- BCR-09 Disaster Response Plan: CP-02, CP-10, IR-01 (82%)
- BCR-10 Response Plan Exercise: CP-04, IR-03 (85%)
- BCR-11 Equipment Redundancy: CP-07, CP-08, PE-11 (78%)
- CCC-01 Change Management Policy and Procedures: CM-01, CM-03, CM-09 (88%)
- CCC-02 Quality Testing: CM-03, SA-11, CM-04 (80%)
- CCC-03 Change Management Technology: CM-03, CM-05, CM-09 (75%)
- CCC-04 Unauthorized Change Protection: CM-03, CM-05, SI-07 (85%)
- CCC-05 Change Agreements: CM-03, SA-04 (70%)
- CCC-06 Change Management Baseline: CM-02, CM-06 (88%)
- CCC-07 Detection of Baseline Deviation: CM-02, SI-07, CM-03 (82%)
- CCC-08 Exception Management: CM-03, CA-05, PL-02 (70%)
- CCC-09 Change Restoration: CM-03, CP-10, CP-09 (78%)
- CEK-01 Encryption and Key Management Policy and Procedures: SC-12, SC-13, SC-01 (85%)
- CEK-02 CEK Roles and Responsibilities: SC-12, PS-01, PL-02 (72%)
- CEK-03 Data Encryption: SC-13, SC-28, SC-08 (88%)
- CEK-04 Encryption Algorithm: SC-13 (85%)
- CEK-05 Encryption Change Management: SC-13, CM-03 (72%)
- CEK-06 Encryption Change Cost Benefit Analysis: SC-13, RA-03 (55%)
- CEK-07 Encryption Risk Management: SC-13, RA-03, RA-07 (75%)
- CEK-08 CSC Key Management Capability: SC-12 (50%)
- CEK-09 Encryption and Key Management Audit: SC-12, AU-02, CA-02 (75%)
- CEK-10 Key Generation: SC-12, SC-13 (82%)
- CEK-11 Key Purpose: SC-12 (72%)
- CEK-12 Key Rotation: SC-12 (75%)
- CEK-13 Key Revocation: SC-12, SC-17 (78%)
- CEK-14 Key Destruction: SC-12, MP-06 (80%)
- CEK-15 Key Activation: SC-12 (70%)
- CEK-16 Key Suspension: SC-12 (65%)
- CEK-17 Key Deactivation: SC-12 (68%)
- CEK-18 Key Archival: SC-12, CP-09 (70%)
- CEK-19 Key Compromise: SC-12, IR-06, IR-01 (75%)
- CEK-20 Key Recovery: SC-12, CP-09 (72%)
- CEK-21 Key Inventory Management: SC-12, CM-08 (72%)
- DCS-01 Off-Site Equipment Disposal Policy and Procedures: MP-06, PE-01 (82%)
- DCS-02 Off-Site Transfer Authorization Policy and Procedures: MP-05, PE-01, PE-16 (82%)
- DCS-03 Secure Area Policy and Procedures: PE-01, PE-02, PE-03 (88%)
- DCS-04 Secure Media Transportation Policy and Procedures: MP-05, MP-01 (85%)
- DCS-05 Assets Classification: CM-08, RA-02, MP-04 (80%)
- DCS-06 Assets Cataloguing and Tracking: CM-08, PE-05 (78%)
- DCS-07 Controlled Access Points: PE-03, PE-06 (88%)
- DCS-08 Equipment Identification: CM-08, IA-03 (78%)
- DCS-09 Secure Area Authorization: PE-02, PE-03 (88%)
- DCS-10 Surveillance System: PE-06, PE-08 (85%)
- DCS-11 Unauthorized Access Response Training: AT-03, PE-06, IR-02 (75%)
- DCS-12 Cabling Security: PE-04, PE-09 (85%)
- DCS-13 Environmental Systems: PE-13, PE-14, PE-15 (88%)
- DCS-14 Secure Utilities: PE-09, PE-10, PE-11 (85%)
- DCS-15 Equipment Location: PE-18, PE-05 (72%)
- DSP-01 Security and Privacy Policy and Procedures: PT-01, PL-01, AC-01 (82%)
- DSP-02 Secure Disposal: MP-06, SI-12 (85%)
- DSP-03 Data Inventory: CM-08, PM-05, PT-03 (72%)
- DSP-04 Data Classification: RA-02, AC-16 (80%)
- DSP-05 Data Flow Documentation: PL-02, AC-04, CA-09 (75%)
- DSP-06 Data Ownership and Stewardship: PM-05, AC-16, PT-01 (60%)
- DSP-07 Data Protection by Design and Default: SA-08, PT-01, SC-28 (72%)
- DSP-08 Data Privacy by Design and Default: PT-01, PT-02, PT-03 (75%)
- DSP-09 Data Protection Impact Assessment: PT-01, RA-03, RA-08 (70%)
- DSP-10 Sensitive Data Transfer: SC-08, SC-13, AC-04 (82%)
- DSP-11 Personal Data Access, Reversal, Rectification and Deletion: PT-04, PT-05, PT-06 (72%)
- DSP-12 Limitation of Purpose in Personal Data Processing: PT-02, PT-03 (78%)
- DSP-13 Personal Data Sub-processing: PT-01, SA-04, SA-09 (62%)
- DSP-14 Disclosure of Data Sub-processors: SA-09, PT-01 (55%)
- DSP-15 Limitation of Production Data Use: PT-03, CM-04 (62%)
- DSP-16 Data Retention and Deletion: SI-12, MP-06, PT-01 (78%)
- DSP-17 Sensitive Data Protection: SC-28, SC-08, AC-03 (82%)
- DSP-18 Disclosure Notification: IR-06, PT-01 (65%)
- DSP-19 Data Location: PT-01, SA-09 (45%)
- GRC-01 Governance Program Policy and Procedures: PL-01, PM-01, PM-02 (85%)
- GRC-02 Risk Management Program: RA-01, RA-03, PM-09 (85%)
- GRC-03 Organizational Policy Reviews: PL-01, PM-01 (80%)
- GRC-04 Policy Exception Process: PL-02, CA-05 (72%)
- GRC-05 Information Security Program: PM-01, PM-02, PM-03 (85%)
- GRC-06 Governance Responsibility Model: PM-02, PL-02, PM-01 (68%)
- GRC-07 Information System Regulatory Mapping: PM-01, PL-02, CA-02 (65%)
- GRC-08 Special Interest Groups: PM-15, PM-16 (78%)
- HRS-01 Background Screening Policy and Procedures: PS-01, PS-03 (88%)
- HRS-02 Acceptable Use of Technology Policy and Procedures: PL-04, AC-20 (85%)
- HRS-03 Clean Desk Policy and Procedures: MP-02, AC-11 (72%)
- HRS-04 Remote and Home Working Policy and Procedures: AC-17, PE-17 (82%)
- HRS-05 Asset returns: PS-04 (80%)
- HRS-06 Employment Termination: PS-04, PS-05 (88%)
- HRS-07 Employment Agreement Process: PS-06, PS-01 (80%)
- HRS-08 Employment Agreement Content: PS-06, PL-04 (78%)
- HRS-09 Personnel Roles and Responsibilities: PS-01, PL-02, PM-02 (82%)
- HRS-10 Non-Disclosure Agreements: PS-06, PS-09 (80%)
- HRS-11 Security Awareness Training: AT-01, AT-02, AT-03 (88%)
- HRS-12 Personal and Sensitive Data Awareness and Training: AT-02, AT-03, PT-01 (78%)
- HRS-13 Compliance User Responsibility: PL-04, PS-06, AT-02 (78%)
- IAM-01 Identity and Access Management Policy and Procedures: AC-01, IA-01 (88%)
- IAM-02 Strong Password Policy and Procedures: IA-05, IA-01 (85%)
- IAM-03 Identity Inventory: AC-02, IA-04 (82%)
- IAM-04 Separation of Duties: AC-05, AC-06 (88%)
- IAM-05 Least Privilege: AC-06, AC-02 (90%)
- IAM-06 User Access Provisioning: AC-02, IA-04, IA-05 (88%)
- IAM-07 User Access Changes and Revocation: AC-02, PS-04, PS-05 (88%)
- IAM-08 User Access Review: AC-02, AC-06 (85%)
- IAM-09 Segregation of Privileged Access Roles: AC-05, AC-06 (85%)
- IAM-10 Management of Privileged Access Roles: AC-02, AC-06, IA-02 (85%)
- IAM-11 CSCs Approval for Agreed Privileged Access Roles: AC-02, AC-06 (60%)
- IAM-12 Safeguard Logs Integrity: AU-09, AU-10 (85%)
- IAM-13 Uniquely Identifiable Users: IA-02, IA-04, AC-02 (90%)
- IAM-14 Strong Authentication: IA-02, IA-05, IA-08 (88%)
- IAM-15 Passwords Management: IA-05, IA-02 (85%)
- IAM-16 Authorization Mechanisms: AC-03, AC-06, AC-16 (85%)
- IPY-01 Interoperability and Portability Policy and Procedures: SA-01, SA-04 (55%)
- IPY-02 Application Interface Availability: SA-04, SA-09 (52%)
- IPY-03 Secure Interoperability and Portability Management: SA-04, SC-08, SA-09 (55%)
- IPY-04 Data Portability Contractual Obligations: SA-04 (42%)
- IVS-01 Infrastructure and Virtualization Security Policy and Procedures: SC-01, CM-01, SA-01 (78%)
- IVS-02 Capacity and Resource Planning: SC-05, SC-06, CP-02 (65%)
- IVS-03 Network Security: SC-07, SC-08, AC-04 (85%)
- IVS-04 OS Hardening and Base Controls: CM-06, CM-02, SI-02 (85%)
- IVS-05 Production and Non-Production Environments: CM-02, CM-04, SC-07 (78%)
- IVS-06 Segmentation and Segregation: SC-07, AC-04, SC-03 (82%)
- IVS-07 Migration to Cloud Environments: SA-03, CM-03, SA-04 (55%)
- IVS-08 Network Architecture Documentation: PL-02, SC-07, CA-09 (78%)
- IVS-09 Network Defense: SC-07, SI-04, SC-05 (85%)
- LOG-01 Logging and Monitoring Policy and Procedures: AU-01, AU-02 (88%)
- LOG-02 Audit Logs Protection: AU-09, AU-11 (88%)
- LOG-03 Security Monitoring and Alerting: SI-04, AU-06, CA-07 (88%)
- LOG-04 Audit Logs Access and Accountability: AU-09, AU-06, AC-06 (85%)
- LOG-05 Audit Logs Monitoring and Response: AU-06, SI-04, IR-04 (85%)
- LOG-06 Clock Synchronization: AU-08 (90%)
- LOG-07 Logging Scope: AU-02, AU-03 (85%)
- LOG-08 Log Records: AU-03, AU-02 (88%)
- LOG-09 Log Protection: AU-09, AU-11 (88%)
- LOG-10 Encryption Monitoring and Reporting: AU-02, SC-13, CA-07 (68%)
- LOG-11 Transaction/Activity Logging: AU-02, AU-03, AU-12 (88%)
- LOG-12 Access Control Logs: AU-02, AU-03, AC-02 (85%)
- LOG-13 Failures and Anomalies Reporting: AU-05, SI-04, AU-06 (82%)
- SEF-01 Security Incident Management Policy and Procedures: IR-01, IR-08 (88%)
- SEF-02 Service Management Policy and Procedures: IR-01, IR-04, PM-01 (75%)
- SEF-03 Incident Response Plans: IR-08, IR-04, IR-02 (88%)
- SEF-04 Incident Response Testing: IR-03 (88%)
- SEF-05 Incident Response Metrics: IR-04, CA-07, PM-06 (72%)
- SEF-06 Event Triage Processes: IR-04, IR-05, AU-06 (82%)
- SEF-07 Security Breach Notification: IR-06, IR-07 (78%)
- SEF-08 Points of Contact Maintenance: IR-06, IR-01, PM-15 (78%)
- STA-01 SSRM Policy and Procedures: SR-01, SA-01, PM-01 (68%)
- STA-02 SSRM Supply Chain: SR-01, SR-02, SR-03 (72%)
- STA-03 SSRM Guidance: SR-01, SA-04 (58%)
- STA-04 SSRM Control Ownership: SR-01, PM-02 (55%)
- STA-05 SSRM Documentation Review: SR-01, CA-02 (60%)
- STA-06 SSRM Control Implementation: SR-01, CA-02, SA-09 (62%)
- STA-07 Supply Chain Inventory: SR-01, SR-02, CM-08 (75%)
- STA-08 Supply Chain Risk Management: SR-01, SR-02, SR-03, RA-03 (82%)
- STA-09 Primary Service and Contractual Agreement: SA-04, SA-09 (72%)
- STA-10 Supply Chain Agreement Review: SA-04, SR-01 (70%)
- STA-11 Internal Compliance Testing: CA-02, CA-07 (82%)
- STA-12 Supply Chain Service Agreement Compliance: SA-09, CA-02, SR-01 (72%)
- STA-13 Supply Chain Governance Review: SR-01, PM-01, CA-02 (72%)
- STA-14 Supply Chain Data Security Assessment: SR-01, SR-03, RA-03 (72%)
- TVM-01 Threat and Vulnerability Management Policy and Procedures: RA-01, RA-05, SI-01 (85%)
- TVM-02 Malware Protection Policy and Procedures: SI-03, SI-01 (85%)
- TVM-03 Vulnerability Remediation Schedule: RA-05, SI-02 (82%)
- TVM-04 Detection Updates: SI-03, SI-02 (85%)
- TVM-05 External Library Vulnerabilities: RA-05, SA-11, SR-04 (78%)
- TVM-06 Penetration Testing: CA-08, RA-05 (85%)
- TVM-07 Vulnerability Identification: RA-05, SI-05 (85%)
- TVM-08 Vulnerability Prioritization: RA-05, RA-03 (80%)
- TVM-09 Vulnerability Management Reporting: RA-05, CA-07, PM-06 (78%)
- TVM-10 Vulnerability Management Metrics: RA-05, PM-06, CA-07 (72%)
- UEM-01 Endpoint Devices Policy and Procedures: CM-01, AC-19, SC-42 (82%)
- UEM-02 Application and Service Approval: CM-07, CM-11 (80%)
- UEM-03 Compatibility: CM-02, SA-04 (65%)
- UEM-04 Endpoint Inventory: CM-08 (85%)
- UEM-05 Endpoint Management: CM-02, CM-06, CM-03 (82%)
- UEM-06 Automatic Lock Screen: AC-11 (88%)
- UEM-07 Operating Systems: CM-06, CM-02, SI-02 (82%)
- UEM-08 Storage Encryption: SC-28, SC-13 (88%)
- UEM-09 Anti-Malware Detection and Prevention: SI-03 (88%)
- UEM-10 Software Firewall: SC-07, CM-07 (82%)
- UEM-11 Data Loss Prevention: SC-07, AC-04, SI-04 (75%)
- UEM-12 Remote Locate: CM-08 (55%)
- UEM-13 Remote Wipe: MP-06, AC-19 (72%)
- UEM-14 Third-Party Endpoint Security Posture: SA-09, AC-20, SR-01 (65%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=csa_ccm_v4
- Control-to-clause mappings as JSON: /api/v1/frameworks/csa_ccm_v4?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/csa-ccm-v4.json
- Page for people: /frameworks/csa-ccm-v4/
