CCSP · Question #126
You are the security policy lead for your organization, which is considering migrating from your on- premises, legacy environment into the cloud. You are reviewing the Cloud Security Alliance Cloud Co
The correct answer is B. Allowing your organization to leverage existing controls across multiple frameworks so as not to. The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) primarily benefits organizations by providing a comprehensive framework that maps cloud security controls to various industry standards and regulations, allowing for efficient leveraging of controls across multiple com
Question
You are the security policy lead for your organization, which is considering migrating from your on- premises, legacy environment into the cloud. You are reviewing the Cloud Security Alliance Cloud Controls Matrix (CSA CCM) as a tool for your organization. What is probably the best benefit offered by the CCM?
Options
- AThe low cost of the tool
- BAllowing your organization to leverage existing controls across multiple frameworks so as not to
- CSimplicity of control selection from the list of approved choices
- DEase of implementation by choosing controls from the list of qualified vendors
How the community answered
(29 responses)- B90% (26)
- C3% (1)
- D7% (2)
Why each option
The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) primarily benefits organizations by providing a comprehensive framework that maps cloud security controls to various industry standards and regulations, allowing for efficient leveraging of controls across multiple compliance requirements.
While the CCM document itself is freely available, the benefit isn't primarily about its low cost but its utility as a comprehensive mapping tool.
The CSA CCM provides a standardized set of security controls specifically for cloud computing and maps these controls to numerous existing security standards, regulations, and frameworks (e.g., ISO 27001, HIPAA, PCI DSS). This cross-referencing allows organizations to assess their cloud security posture against multiple compliance requirements simultaneously and leverage a single set of controls to meet diverse obligations, reducing redundant effort.
The CCM is a comprehensive list of controls, but its primary benefit isn't *simplicity of selection*; rather, it's the *comprehensiveness and mapping* that adds value, which can actually be complex.
The CCM provides controls, but it does not directly facilitate the *ease of implementation* by providing a list of qualified vendors; that would be a separate procurement process.
Concept tested: CSA CCM benefits and purpose
Source: https://cloudsecurityalliance.org/research/artifacts/cloud-controls-matrix/
Topics
Community Discussion
No community discussion yet for this question.