Beyond SOC 2
What is CSA and CCM?
What is CSA and CCM?
CSA is the Cloud Security Alliance, a nonprofit organization that publishes security best practices for cloud computing. CCM is its Cloud Controls Matrix, a control framework written specifically for cloud services. Version 4.1 of the CCM contains 207 controls across 17 domains and maps to ISO 27001, NIST SP 800-53, PCI DSS, and other standards. CSA also runs the STAR program, which lets cloud providers publish self-assessments or third-party validation against the CCM.
What the Cloud Controls Matrix covers
The CCM's 17 domains cover the ground of a general security framework, with more attention to how responsibility splits between a cloud provider and its customer.
| Area | Domains include | What is cloud-specific |
|---|---|---|
| Governance and risk | Governance, Risk and Compliance; Audit and Assurance | Shared responsibility defined per control |
| Identity and access | Identity and Access Management | Customer versus provider administrative access |
| Data | Data Security and Privacy Lifecycle Management; Cryptography, Encryption and Key Management | Data location, tenant separation, customer-managed keys |
| Infrastructure | Infrastructure and Virtualization Security; Datacenter Security | Hypervisor and multi-tenant isolation |
| Operations | Logging and Monitoring; Threat and Vulnerability Management; Change Control and Configuration Management | Visibility customers can get into provider operations |
| Supply chain | Supply Chain Management, Transparency, and Accountability | Controls on the provider's own cloud subprocessors |
| Resilience | Business Continuity Management and Operational Resilience; Security Incident Management, E-Discovery, and Cloud Forensics | Provider versus customer recovery obligations |
Since version 4, the CCM includes shared security responsibility guidance that assigns each control to the cloud provider, the customer, or both. That split is the main thing the CCM adds over a general catalog such as ISO 27001 Annex A.
CSA STAR levels
| Level | What it is | Who performs it |
|---|---|---|
| Level 1: Self-Assessment | Completed CAIQ questionnaire published in the STAR Registry | The provider itself |
| Level 2: Certification | ISO 27001 certification audit extended to cover the CCM | An accredited certification body |
| Level 2: Attestation | SOC 2 examination extended to cover the CCM criteria | A licensed CPA firm |
The STAR Registry is public, so a buyer can look up a provider's submission without asking for it. Level 1 costs nothing to publish, which is why many SaaS vendors use it to answer cloud-specific questionnaires before pursuing a formal audit.
Where the CCM fits for a SaaS company
For most B2B SaaS companies, the CCM is a complement to SOC 2 or ISO 27001 rather than a replacement. Buyers ask for those two by name. The CCM becomes useful in two situations: when a customer sends the CAIQ as its security questionnaire, and when a company already running SOC 2 or ISO 27001 wants STAR Level 2 by adding the CCM to an existing audit instead of starting a new one. Because the CCM maps to both, much of the evidence is already collected. For how the underlying frameworks overlap, see the controls shared by SOC 2, ISO 27001, and HIPAA.