Home
Use cases
By framework
CSA CCM

Harden your cloud security with Cloud Controls Matrix

CCM presents you best practices for cloud technology aspects of security. Use it to expand on already good security management and control related risks better.

Tietosuojamalliin luottavat isot ja pienet, yritykset, kunnat ja järjestöt.

What is CSA CCM?

Cloud Controls Matrix (CCM) is a cyber security control framework for cloud computing developed by Cloud Security Alliance. It is composed of 197 control objectives that are structured in 17 domains covering all key aspects of cloud technology. It is a popular framework for hardening the cloud technology aspects of your cyber security.

Here's how Cyberday simplifies your CSA CCM compliance:

Automated report visualizes your CSA CCM compliance

Framework requirements are implemented in Cyberday through tasks. Once you activate tasks and define their implementation status, the report will automatically start turning greener. See details by clicking each cell in the report and understand how to improve!

Understand what needs improving and how to do it

Pending tasks in your account will help you get compliant and also go further then the minimum compliance level. First you understand how to get compliant and later you understand how to harden your security even more on each aspect.

Create an asset inventory in clear parts

Cyberday has own sections for data systems, data sets, other assets (e.g. equipment) and physical premises. With the help of these you understand the assets your cyber security aims to protect.

Identify, evaluate and treat information security risks

When you're documenting e.g. results of risk management or a continuity plan, the documentation card will mostly function similarly, but there's a clear order to use.

Automated employee guidance and awareness training

A big part of information security is ensuring the safe operations of organization's staff. Many tasks will require you to define guidelines for people to follow. These will be accepted through Guidebook, which can also be expanded with training material. Policy templates are also available, if you want to create a shareable document from your content.