nerdexam
(ISC)2

CCSP · Question #126

You are the security policy lead for your organization, which is considering migrating from your on- premises, legacy environment into the cloud. You are reviewing the Cloud Security Alliance Cloud Co

The correct answer is B. Allowing your organization to leverage existing controls across multiple frameworks so as not to. The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) primarily benefits organizations by providing a comprehensive framework that maps cloud security controls to various industry standards and regulations, allowing for efficient leveraging of controls across multiple com

Submitted by yasin.bd· Apr 18, 2026Legal, Risk and Compliance

Question

You are the security policy lead for your organization, which is considering migrating from your on- premises, legacy environment into the cloud. You are reviewing the Cloud Security Alliance Cloud Controls Matrix (CSA CCM) as a tool for your organization. What is probably the best benefit offered by the CCM?

Options

  • AThe low cost of the tool
  • BAllowing your organization to leverage existing controls across multiple frameworks so as not to
  • CSimplicity of control selection from the list of approved choices
  • DEase of implementation by choosing controls from the list of qualified vendors

How the community answered

(29 responses)
  • B
    90% (26)
  • C
    3% (1)
  • D
    7% (2)

Why each option

The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) primarily benefits organizations by providing a comprehensive framework that maps cloud security controls to various industry standards and regulations, allowing for efficient leveraging of controls across multiple compliance requirements.

AThe low cost of the tool

While the CCM document itself is freely available, the benefit isn't primarily about its low cost but its utility as a comprehensive mapping tool.

BAllowing your organization to leverage existing controls across multiple frameworks so as not toCorrect

The CSA CCM provides a standardized set of security controls specifically for cloud computing and maps these controls to numerous existing security standards, regulations, and frameworks (e.g., ISO 27001, HIPAA, PCI DSS). This cross-referencing allows organizations to assess their cloud security posture against multiple compliance requirements simultaneously and leverage a single set of controls to meet diverse obligations, reducing redundant effort.

CSimplicity of control selection from the list of approved choices

The CCM is a comprehensive list of controls, but its primary benefit isn't *simplicity of selection*; rather, it's the *comprehensiveness and mapping* that adds value, which can actually be complex.

DEase of implementation by choosing controls from the list of qualified vendors

The CCM provides controls, but it does not directly facilitate the *ease of implementation* by providing a list of qualified vendors; that would be a separate procurement process.

Concept tested: CSA CCM benefits and purpose

Source: https://cloudsecurityalliance.org/research/artifacts/cloud-controls-matrix/

Topics

#CSA CCM#Cloud Security Frameworks#Control Mapping#Compliance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice