Cloud Controls Matrix v4.0
The Cloud Controls Matrix is a set of controls designed to be used by both cloud service consumers as well as providers. The CCM includes both technical and administrative controls that can be used to provide security for cloud technology adoption or implementations.
| ID | Name | Threats |
|---|---|---|
| AIS-04 | Secure Application Design and Development | STRIDE-LM |
| AIS-07 | Application Vulnerability Remediation | STRIDE-LM |
| CEK-19 | Key Compromise | STRIDE-LM |
| IAM-01 | Identity and Access Management Policy and Procedures | STRIDE-LM |
| IAM-04 | Separation of Duties | STRIDE-LM |
| IAM-05 | Least Privilege | STRIDE-LM |
| IAM-06 | User Access Provisioning | STRIDE-LM |
| IAM-08 | User Access Review | STRIDE-LM |
| IAM-09 | Segregation of Privileged Access Roles | STRIDE-LM |
| IAM-10 | Management of Privileged Access Roles | STRIDE-LM |
| IAM-11 | CSCs Approval for Agreed Privileged Access Roles | STRIDE-LM |
| IAM-16 | Authorization Mechanisms | STRIDE-LM |
| IVS-04 | OS Hardening and Base Controls | STRIDE-LM |
| TVM-03 | Vulnerability Remediation Schedule | STRIDE-LM |
| TVM-05 | External Library Vulnerabilities | STRIDE-LM |
| TVM-06 | Penetration Testing | STRIDE-LM |
| TVM-08 | Vulnerability Prioritization | STRIDE-LM |
| UEM-07 | Operating Systems | STRIDE-LM |