Citations: CSA Cloud Controls Matrix (CCM), V4
No citations match the current filters.
A&A-01 Audit and Assurance Policy and Procedures
SNow
Reference: A&A-01
Establish, document, approve, communicate, apply, evaluate and maintain audit and assurance policies and procedures and standards. Review and update the policies and procedures at least annually.
Authority Document
Mapped Processes (2)
A&A-02 Independent Assessments
SNow
Reference: A&A-02
Conduct independent audit and assurance assessments according to relevant standards at least annually.
Authority Document
Mapped Processes (2)
A&A-03 Risk Based Planning Assessment
SNow
Reference: A&A-03
Perform independent audit and assurance assessments according to
risk-based plans and policies.
Authority Document
Mapped Processes (1)
A&A-04 Requirements Compliance
SNow
Reference: A&A-04
Verify compliance with all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit.
Authority Document
Mapped Processes (2)
A&A-05 Audit Management Process
SNow
Reference: A&A-05
Define and implement an Audit Management process to support audit planning, risk analysis, security control assessment, conclusion, remediation schedules, report generation, and review of past reports and supporting evidence.
Authority Document
Mapped Processes (1)
A&A-06 Remediation
SNow
Reference: A&A-06
Establish, document, approve, communicate, apply, evaluate and maintain a risk-based corrective action plan to remediate audit findings, review and report remediation status to relevant stakeholders.
Authority Document
Mapped Processes (2)
AIS-01 Application and Interface Security Policy and Procedures
SNow
Reference: AIS-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security to provide guidance to the appropriate planning, delivery and support of the organization's application security capabilities. Review and update the policies and procedures at lea
Authority Document
Mapped Processes (1)
AIS-02 Application Security Baseline Requirements
SNow
Reference: AIS-02
Establish, document and maintain baseline requirements for securing different applications.
Authority Document
Mapped Processes (1)
AIS-03 Application Security Metrics
SNow
Reference: AIS-03
Define and implement technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.
Authority Document
Mapped Processes (1)
AIS-04 Secure Application Design and Development
SNow
Reference: AIS-04
Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
Authority Document
Mapped Processes (2)
AIS-05 Automated Application Security Testing
SNow
Reference: AIS-05
Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.
Authority Document
AIS-06 Automated Secure Application Deployment
SNow
Reference: AIS-06
Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.
Authority Document
Mapped Processes (2)
AIS-07 Application Vulnerability Remediation
SNow
Reference: AIS-07
Define and implement a process to remediate application security vulnerabilities, automating remediation when possible.
Authority Document
Mapped Processes (2)
BCR-01 Business Continuity Management Policy and Procedures
SNow
Reference: BCR-01
Establish, document, approve, communicate, apply, evaluate and maintain business continuity management and operational resilience policies and procedures. Review and update the policies and procedures at least annually.
Authority Document
BCR-02 Risk Assessment and Impact Analysis
SNow
Reference: BCR-02
Determine the impact of business disruptions and risks to establish criteria for developing business continuity and operational resilience strategies and capabilities.
Authority Document
BCR-03 Business Continuity Strategy
SNow
Reference: BCR-03
Establish strategies to reduce the impact of, withstand, and recover from business disruptions within risk appetite.
Authority Document
BCR-04 Business Continuity Planning
SNow
Reference: BCR-04
Establish, document, approve, communicate, apply, evaluate and maintain a business continuity plan based on the results of the operational resilience strategies and capabilities.
Authority Document
BCR-05 Documentation
SNow
Reference: BCR-05
Develop, identify, and acquire documentation that is relevant to support the business continuity and operational resilience programs. Make the documentation available to authorized stakeholders and review periodically.
Authority Document
BCR-06 Business Continuity Exercises
SNow
Reference: BCR-06
Exercise and test business continuity and operational resilience plans at least annually or upon significant changes.
Authority Document
BCR-07 Communication
SNow
Reference: BCR-07
Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.
Authority Document
Mapped Processes (1)
BCR-08 Backup
SNow
Reference: BCR-08
Periodically backup data stored in the cloud. Ensure the confidentiality, integrity and availability of the backup, and verify data restoration from backup for resiliency.
Authority Document
Mapped Processes (1)
BCR-09 Disaster Response Plan
SNow
Reference: BCR-09
Establish, document, approve, communicate, apply, evaluate and maintain a disaster response plan to recover from natural and man-made disasters. Update the plan at least annually or upon significant changes.
Authority Document
BCR-10 Response Plan Exercise
SNow
Reference: BCR-10
Exercise the disaster response plan annually or upon significant changes, including if possible local emergency authorities.
Authority Document
BCR-11 Equipment Redundancy
SNow
Reference: BCR-11
Supplement business-critical equipment with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards.
Authority Document
CCC-01 Change Management Policy and Procedures
SNow
Reference: CCC-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for managing the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally
Authority Document
CCC-02 Quality Testing
SNow
Reference: CCC-02
Follow a defined quality change control, approval and testing process with established baselines, testing, and release standards.
CCC-03 Change Management Technology
SNow
Reference: CCC-03
Manage the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally or externally (i.e., outsourced).
Authority Document
CCC-04 Unauthorized Change Protection
SNow
Reference: CCC-04
Restrict the unauthorized addition, removal, update, and management of organization assets.
Authority Document
CCC-05 Change Agreements
SNow
Reference: CCC-05
Include provisions limiting changes directly impacting CSCs owned environments/tenants to explicitly authorized requests within service level agreements between CSPs and CSCs.
Authority Document
Mapped Processes (1)
CCC-06 Change Management Baseline
SNow
Reference: CCC-06
Establish change management baselines for all relevant authorized changes on organization assets.
Authority Document
Mapped Processes (2)
CCC-07 Detection of Baseline Deviation
SNow
Reference: CCC-07
Implement detection measures with proactive notification in case of changes deviating from the established baseline.
Authority Document
Mapped Processes (2)
CCC-08 Exception Management
SNow
Reference: CCC-08
Implement a procedure for the management of exceptions, including emergencies, in the change and configuration process. Align the procedure with the requirements of GRC-04: Policy Exception Process.'
Authority Document
Mapped Processes (2)
CCC-09 Change Restoration
SNow
Reference: CCC-09
Define and implement a process to proactively roll back changes to a previous known good state in case of errors or security concerns.
Authority Document
Mapped Processes (2)
CEK-01 Encryption and Key Management Policy and Procedures
SNow
Reference: CEK-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Cryptography, Encryption and Key Management. Review and update the policies and procedures at least annually.
Authority Document
CEK-02 CEK Roles and Responsibilities
SNow
Reference: CEK-02
Define and implement cryptographic, encryption and key management roles and responsibilities.
Authority Document
CEK-03 Data Encryption
SNow
Reference: CEK-03
Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.
Authority Document
CEK-04 Encryption Algorithm
SNow
Reference: CEK-04
Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.
Authority Document
CEK-05 Encryption Change Management
SNow
Reference: CEK-05
Establish a standard change management procedure, to accommodate changes from internal and external sources, for review, approval, implementation and communication of cryptographic, encryption and key management technology changes.
Authority Document
CEK-06 Encryption Change Cost Benefit Analysis
SNow
Reference: CEK-06
Manage and adopt changes to cryptography-, encryption-, and key management-related systems (including policies and procedures) that fully account for downstream effects of proposed changes, including residual risk, cost, and benefits analysis.
Authority Document
CEK-07 Encryption Risk Management
SNow
Reference: CEK-07
Establish and maintain an encryption and key management risk program that includes provisions for risk assessment, risk treatment, risk context, monitoring, and feedback.
Authority Document
Mapped Processes (1)
CEK-08 CSC Key Management Capability
SNow
Reference: CEK-08
CSPs must provide the capability for CSCs to manage their own data encryption keys.
Authority Document
CEK-09 Encryption and Key Management Audit
SNow
Reference: CEK-09
Audit encryption and key management systems, policies, and processes with a frequency that is proportional to the risk exposure of the system with audit occurring preferably continuously but at least annually and after any security event(s).
Authority Document
Mapped Processes (1)
CEK-10 Key Generation
SNow
Reference: CEK-10
Generate Cryptographic keys using industry accepted cryptographic libraries specifying the algorithm strength and the random number generator used.
Authority Document
CEK-11 Key Purpose
SNow
Reference: CEK-11
Manage cryptographic secret and private keys that are provisioned for a unique purpose.
Authority Document
CEK-12 Key Rotation
SNow
Reference: CEK-12
Rotate cryptographic keys in accordance with the calculated cryptoperiod, which includes provisions for considering the risk of information disclosure and legal and regulatory requirements.
Authority Document
CEK-13 Key Revocation
SNow
Reference: CEK-13
Define, implement and evaluate processes, procedures and technical measures to revoke and remove cryptographic keys prior to the end of its established cryptoperiod, when a key is compromised, or an entity is no longer part of the organization, which include provisions for legal and regulatory requi
Authority Document
CEK-14 Key Destruction
SNow
Reference: CEK-14
Define, implement and evaluate processes, procedures and technical measures to destroy keys stored outside a secure environment and revoke keys stored in Hardware Security Modules (HSMs) when they are no longer needed, which include provisions for legal and regulatory requirements.
Authority Document
CEK-15 Key Activation
SNow
Reference: CEK-15
Define, implement and evaluate processes, procedures and technical measures to create keys in a pre-activated state when they have been generated but not authorized for use, which include provisions for legal and regulatory requirements.
Authority Document
CEK-16 Key Suspension
SNow
Reference: CEK-16
Define, implement and evaluate processes, procedures and technical measures to monitor, review and approve key transitions from any state to/from suspension, which include provisions for legal and regulatory requirements.
Authority Document
CEK-17 Key Deactivation
SNow
Reference: CEK-17
Define, implement and evaluate processes, procedures and technical measures to deactivate keys at the time of their expiration date, which include provisions for legal and regulatory requirements.
Authority Document
CEK-18 Key Archival
SNow
Reference: CEK-18
Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.
Authority Document
CEK-19 Key Compromise
SNow
Reference: CEK-19
Define, implement and evaluate processes, procedures and technical measures to use compromised keys to encrypt information only in controlled circumstance, and thereafter exclusively for decrypting data and never for encrypting data, which include provisions for legal and regulatory requirements.
Authority Document
CEK-20 Key Recovery
SNow
Reference: CEK-20
Define, implement and evaluate processes, procedures and technical measures to assess the risk to operational continuity versus the risk of the keying material and the information it protects being exposed if control of the keying material is lost, which include provisions for legal and regulatory r
Authority Document
CEK-21 Key Inventory Management
SNow
Reference: CEK-21
Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.
Authority Document
DCS-01 Off-Site Equipment Disposal Policy and Procedures
SNow
Reference: DCS-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure disposal of equipment used outside the organization's premises. If the equipment is not physically destroyed a data destruction procedure that renders recovery of information impossible mus
Authority Document
DCS-02 Off-Site Transfer Authorization Policy and Procedures
SNow
Reference: DCS-02
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable autho
Authority Document
DCS-03 Secure Area Policy and Procedures
SNow
Reference: DCS-03
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities. Review and update the policies and procedures at least annually.
Authority Document
DCS-04 Secure Media Transportation Policy and Procedures
SNow
Reference: DCS-04
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure transportation of physical media. Review and update the policies and procedures at least annually.
Authority Document
DCS-05 Assets Classification
SNow
Reference: DCS-05
Classify and document the physical, and logical assets (e.g., applications) based on the organizational business risk.
Authority Document
Mapped Processes (1)
DCS-06 Assets Cataloguing and Tracking
SNow
Reference: DCS-06
Catalogue and track all relevant physical and logical assets located at all of the CSP's sites within a secured system.
Authority Document
Mapped Processes (1)
DCS-07 Controlled Access Points
SNow
Reference: DCS-07
Implement physical security perimeters to safeguard personnel, data, and information systems. Establish physical security perimeters between the administrative and business areas and the data storage and processing facilities areas.
Authority Document
DCS-08 Equipment Identification
SNow
Reference: DCS-08
Use equipment identification as a method for connection authentication.
Authority Document
DCS-09 Secure Area Authorization
SNow
Reference: DCS-09
Allow only authorized personnel access to secure areas, with all ingress and egress points restricted, documented, and monitored by physical access control mechanisms. Retain access control records on a periodic basis as deemed appropriate by the organization.
Authority Document
DCS-10 Surveillance System
SNow
Reference: DCS-10
Implement, maintain, and operate datacenter surveillance systems at the external perimeter and at all the ingress and egress points to detect unauthorized ingress and egress attempts.
Authority Document
DCS-11 Unauthorized Access Response Training
SNow
Reference: DCS-11
Train datacenter personnel to respond to unauthorized ingress or egress attempts.
Authority Document
DCS-12 Cabling Security
SNow
Reference: DCS-12
Define, implement and evaluate processes, procedures and technical measures that ensure a risk-based protection of power and telecommunication cables from a threat of interception, interference or damage at all facilities, offices and rooms.
Authority Document
DCS-13 Environmental Systems
SNow
Reference: DCS-13
Implement and maintain data center environmental control systems that monitor, maintain and test for continual effectiveness the temperature and humidity conditions within accepted industry standards.
Authority Document
DCS-14 Secure Utilities
SNow
Reference: DCS-14
Secure, monitor, maintain, and test utilities services for continual effectiveness at planned intervals.
Authority Document
DCS-15 Equipment Location
SNow
Reference: DCS-15
Keep business-critical equipment away from locations subject to high probability for environmental risk events.
Authority Document
DSP-01 Security and Privacy Policy and Procedures
SNow
Reference: DSP-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the classification, protection and handling of data throughout its lifecycle, and according to all applicable laws and regulations, standards, and risk level. Review and update the policies and proced
Authority Document
DSP-02 Secure Disposal
SNow
Reference: DSP-02
Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means.
Authority Document
Mapped Processes (2)
DSP-03 Data Inventory
SNow
Reference: DSP-03
Create and maintain a data inventory, at least for any sensitive data and personal data.
Authority Document
Mapped Processes (1)
DSP-04 Data Classification
SNow
Reference: DSP-04
Classify data according to its type and sensitivity level.
Authority Document
DSP-05 Data Flow Documentation
SNow
Reference: DSP-05
Create data flow documentation to identify what data is processed, stored or transmitted where. Review data flow documentation at defined intervals, at least annually, and after any change.
Authority Document
Mapped Processes (1)
DSP-06 Data Ownership and Stewardship
SNow
Reference: DSP-06
Document ownership and stewardship of all relevant documented personal and sensitive data. Perform review at least annually.
Authority Document
Mapped Processes (1)
DSP-07 Data Protection by Design and Default
SNow
Reference: DSP-07
Develop systems, products, and business practices based upon a principle of security by design and industry best practices.
Authority Document
Mapped Processes (1)
DSP-08 Data Privacy by Design and Default
SNow
Reference: DSP-08
Develop systems, products, and business practices based upon a principle of privacy by design and industry best practices. Ensure that systems' privacy settings are configured by default, according to all applicable laws and regulations.
Authority Document
DSP-09 Data Protection Impact Assessment
SNow
Reference: DSP-09
Conduct a Data Protection Impact Assessment (DPIA) to evaluate the origin, nature, particularity and severity of the risks upon the processing of personal data, according to any applicable laws, regulations and industry best practices.
Authority Document
DSP-10 Sensitive Data Transfer
SNow
Reference: DSP-10
Define, implement and evaluate processes, procedures and technical measures that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations.
Authority Document
Mapped Processes (1)
DSP-11 Personal Data Access, Reversal, Rectification and Deletion
SNow
Reference: DSP-11
Define and implement, processes, procedures and technical measures to enable data subjects to request access to, modification, or deletion of their personal data, according to any applicable laws and regulations.
Authority Document
DSP-12 Limitation of Purpose in Personal Data Processing
SNow
Reference: DSP-12
Define, implement and evaluate processes, procedures and technical measures to ensure that personal data is processed according to any applicable laws and regulations and for the purposes declared to the data subject.
Authority Document
DSP-13 Personal Data Sub-processing
SNow
Reference: DSP-13
Define, implement and evaluate processes, procedures and technical measures for the transfer and sub-processing of personal data within the service supply chain, according to any applicable laws and regulations.
Authority Document
DSP-14 Disclosure of Data Sub-processors
SNow
Reference: DSP-14
Define, implement and evaluate processes, procedures and technical measures to disclose the details of any personal or sensitive data access by sub-processors to the data owner prior to initiation of that processing.
Authority Document
DSP-15 Limitation of Production Data Use
SNow
Reference: DSP-15
Obtain authorization from data owners, and manage associated risk before replicating or using production data in non-production environments.
Authority Document
DSP-16 Data Retention and Deletion
SNow
Reference: DSP-16
Data retention, archiving and deletion is managed in accordance with business requirements, applicable laws and regulations.
Authority Document
Mapped Processes (2)
DSP-17 Sensitive Data Protection
SNow
Reference: DSP-17
Define and implement, processes, procedures and technical measures to protect sensitive data throughout it's lifecycle.
Authority Document
DSP-18 Disclosure Notification
SNow
Reference: DSP-18
The CSP must have in place, and describe to CSCs the procedure to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations. The CSP must give special attention to the notification procedure to interested CSCs, unless o
Authority Document
DSP-19 Data Location
SNow
Reference: DSP-19
Define and implement, processes, procedures and technical measures to specify and document the physical locations of data, including any locations in which data is processed or backed up.
Authority Document
GRC-01 Governance Program Policy and Procedures
SNow
Reference: GRC-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.
Authority Document
Mapped Processes (1)
GRC-02 Risk Management Program
SNow
Reference: GRC-02
Establish a formal, documented, and leadership-sponsored Enterprise Risk Management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks.
Authority Document
Mapped Processes (1)
GRC-03 Organizational Policy Reviews
SNow
Reference: GRC-03
Review all relevant organizational policies and associated procedures at least annually or when a substantial change occurs within the organization.
Authority Document
Mapped Processes (2)
GRC-04 Policy Exception Process
SNow
Reference: GRC-04
Establish and follow an approved exception process as mandated by the governance program whenever a deviation from an established policy occurs.
Authority Document
Mapped Processes (2)
GRC-05 Information Security Program
SNow
Reference: GRC-05
Develop and implement an Information Security Program, which includes programs for all the relevant domains of the CCM.
Authority Document
GRC-06 Governance Responsibility Model
SNow
Reference: GRC-06
Define and document roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs.
Authority Document
GRC-07 Information System Regulatory Mapping
SNow
Reference: GRC-07
Identify and document all relevant standards, regulations, legal/contractual, and statutory requirements, which are applicable to your organization.
Authority Document
Mapped Processes (1)
GRC-08 Special Interest Groups
SNow
Reference: GRC-08
Establish and maintain contact with cloud-related special interest groups and other relevant entities in line with business context.
Authority Document
HRS-01 Background Screening Policy and Procedures
SNow
Reference: HRS-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for background verification of all new employees (including but not limited to remote employees, contractors, and third parties) according to local laws, regulations, ethics, and contractual constraints a
Authority Document
HRS-02 Acceptable Use of Technology Policy and Procedures
SNow
Reference: HRS-02
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets. Review and update the policies and procedures at least annually.
Authority Document
HRS-03 Clean Desk Policy and Procedures
SNow
Reference: HRS-03
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures that require unattended workspaces to not have openly visible confidential data. Review and update the policies and procedures at least annually.
Authority Document
HRS-04 Remote and Home Working Policy and Procedures
SNow
Reference: HRS-04
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.
Authority Document
HRS-05 Asset returns
SNow
Reference: HRS-05
Establish and document procedures for the return of organization-owned assets by terminated employees.
Authority Document
HRS-06 Employment Termination
SNow
Reference: HRS-06
Establish, document, and communicate to all personnel the procedures outlining the roles and responsibilities concerning changes in employment.
Authority Document
HRS-07 Employment Agreement Process
SNow
Reference: HRS-07
Employees sign the employee agreement prior to being granted access to organizational information systems, resources and assets.
Authority Document
HRS-08 Employment Agreement Content
SNow
Reference: HRS-08
The organization includes within the employment agreements provisions and/or terms for adherence to established information governance and security policies.
Authority Document
HRS-09 Personnel Roles and Responsibilities
SNow
Reference: HRS-09
Document and communicate roles and responsibilities of employees, as they relate to information assets and security.
Authority Document
Mapped Processes (1)
HRS-10 Non-Disclosure Agreements
SNow
Reference: HRS-10
Identify, document, and review, at planned intervals, requirements for non-disclosure/confidentiality agreements reflecting the organization's needs for the protection of data and operational details.
Authority Document
HRS-11 Security Awareness Training
SNow
Reference: HRS-11
Establish, document, approve, communicate, apply, evaluate and maintain a security awareness training program for all employees of the organization and provide regular training updates.
Authority Document
Mapped Processes (1)
HRS-12 Personal and Sensitive Data Awareness and Training
SNow
Reference: HRS-12
Provide all employees with access to sensitive organizational and personal data with appropriate security awareness training and regular updates in organizational procedures, processes, and policies relating to their professional function relative to the organization.
Authority Document
Mapped Processes (1)
HRS-13 Compliance User Responsibility
SNow
Reference: HRS-13
Make employees aware of their roles and responsibilities for maintaining awareness and compliance with established policies and procedures and applicable legal, statutory, or regulatory compliance obligations.
Authority Document
Mapped Processes (1)
IAM-01 Identity and Access Management Policy and Procedures
SNow
Reference: IAM-01
Establish, document, approve, communicate, implement, apply, evaluate and maintain policies and procedures for identity and access management. Review and update the policies and procedures at least annually.
Authority Document
Mapped Processes (1)
IAM-02 Strong Password Policy and Procedures
SNow
Reference: IAM-02
Establish, document, approve, communicate, implement, apply, evaluate and maintain strong password policies and procedures. Review and update the policies and procedures at least annually.
Authority Document
Mapped Processes (2)
IAM-03 Identity Inventory
SNow
Reference: IAM-03
Manage, store, and review the information of system identities, and level of access.
Authority Document
IAM-04 Separation of Duties
SNow
Reference: IAM-04
Employ the separation of duties principle when implementing information system access.
Authority Document
Mapped Processes (1)
IAM-05 Least Privilege
SNow
Reference: IAM-05
Employ the least privilege principle when implementing information system access.
Authority Document
Mapped Processes (1)
IAM-06 User Access Provisioning
SNow
Reference: IAM-06
Define and implement a user access provisioning process which authorizes, records, and communicates access changes to data and assets.
Authority Document
IAM-07 User Access Changes and Revocation
SNow
Reference: IAM-07
De-provision or respectively modify access of movers / leavers or system identity changes in a timely manner in order to effectively adopt and communicate identity and access management policies.
Authority Document
IAM-08 User Access Review
SNow
Reference: IAM-08
Review and revalidate user access for least privilege and separation of duties with a frequency that is commensurate with organizational risk tolerance.
Authority Document
Mapped Processes (1)
IAM-09 Segregation of Privileged Access Roles
SNow
Reference: IAM-09
Define, implement and evaluate processes, procedures and technical measures for the segregation of privileged access roles such that administrative access to data, encryption and key management capabilities and logging capabilities are distinct and separated.
Authority Document
Mapped Processes (1)
IAM-10 Management of Privileged Access Roles
SNow
Reference: IAM-10
Define and implement an access process to ensure privileged access roles and rights are granted for a time limited period, and implement procedures to prevent the culmination of segregated privileged access.
Authority Document
Mapped Processes (1)
IAM-11 CSCs Approval for Agreed Privileged Access Roles
SNow
Reference: IAM-11
Define, implement and evaluate processes and procedures for customers to participate, where applicable, in the granting of access for agreed, high risk (as defined by the organizational risk assessment) privileged access roles.
Authority Document
IAM-12 Safeguard Logs Integrity
SNow
Reference: IAM-12
Define, implement and evaluate processes, procedures and technical measures to ensure the logging infrastructure is read-only for all with write access, including privileged access roles, and that the ability to disable it is controlled through a procedure that ensures the segregation of duties and
Authority Document
Mapped Processes (1)
IAM-13 Uniquely Identifiable Users
SNow
Reference: IAM-13
Define, implement and evaluate processes, procedures and technical measures that ensure users are identifiable through unique IDs or which can associate individuals to the usage of user IDs.
Authority Document
Mapped Processes (2)
IAM-14 Strong Authentication
SNow
Reference: IAM-14
Define, implement and evaluate processes, procedures and technical measures for authenticating access to systems, application and data assets, including multifactor authentication for at least privileged user and sensitive data access. Adopt digital certificates or alternatives which achieve an equi
Authority Document
Mapped Processes (2)
IAM-15 Passwords Management
SNow
Reference: IAM-15
Define, implement and evaluate processes, procedures and technical measures for the secure management of passwords.
Authority Document
Mapped Processes (2)
IAM-16 Authorization Mechanisms
SNow
Reference: IAM-16
Define, implement and evaluate processes, procedures and technical measures to verify access to data and system functions is authorized.
Authority Document
IPY-01 Interoperability and Portability Policy and Procedures
SNow
Reference: IPY-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for interoperability and portability including requirements for:
a. Communications between application interfaces
b. Information processing interoperability
c. Application development portability
d. Infor
Authority Document
IPY-02 Application Interface Availability
SNow
Reference: IPY-02
Provide application interface(s) to CSCs so that they programmatically retrieve their data to enable interoperability and portability.
Authority Document
IPY-03 Secure Interoperability and Portability Management
SNow
Reference: IPY-03
Implement cryptographically secure and standardized network protocols for the management, import and export of data.
Authority Document
Mapped Processes (1)
IPY-04 Data Portability Contractual Obligations
SNow
Reference: IPY-04
Agreements must include provisions specifying CSCs access to data upon contract termination and will include:
a. Data format
b. Length of time the data will be stored
c. Scope of the data retained and made available to the CSCs
d. Data deletion policy
Authority Document
Mapped Processes (1)
IVS-01 Infrastructure and Virtualization Security Policy and Procedures
SNow
Reference: IVS-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for infrastructure and virtualization security. Review and update the policies and procedures at least annually.
Authority Document
IVS-02 Capacity and Resource Planning
SNow
Reference: IVS-02
Plan and monitor the availability, quality, and adequate capacity of resources in order to deliver the required system performance as determined by the business.
Authority Document
IVS-03 Network Security
SNow
Reference: IVS-03
Monitor, encrypt and restrict communications between environments to only authenticated and authorized connections, as justified by the business. Review these configurations at least annually, and support them by a documented justification of all allowed services, protocols, ports, and compensating
Authority Document
IVS-04 OS Hardening and Base Controls
SNow
Reference: IVS-04
Harden host and guest OS, hypervisor or infrastructure control plane according to their respective best practices, and supported by technical controls, as part of a security baseline.
Authority Document
IVS-05 Production and Non-Production Environments
SNow
Reference: IVS-05
Separate production and non-production environments.
Authority Document
IVS-06 Segmentation and Segregation
SNow
Reference: IVS-06
Design, develop, deploy and configure applications and infrastructures such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented and segregated, monitored and restricted from other tenants.
Authority Document
IVS-07 Migration to Cloud Environments
SNow
Reference: IVS-07
Use secure and encrypted communication channels when migrating servers, services, applications, or data to cloud environments. Such channels must include only up-to-date and approved protocols.
Authority Document
Mapped Processes (1)
IVS-08 Network Architecture Documentation
SNow
Reference: IVS-08
Identify and document high-risk environments.
Authority Document
IVS-09 Network Defense
SNow
Reference: IVS-09
Define, implement and evaluate processes, procedures and defense-in-depth techniques for protection, detection, and timely response to network-based attacks.
Authority Document
LOG-01 Logging and Monitoring Policy and Procedures
SNow
Reference: LOG-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for logging and monitoring. Review and update the policies and procedures at least annually.
Authority Document
LOG-02 Audit Logs Protection
SNow
Reference: LOG-02
Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.
Authority Document
Mapped Processes (1)
LOG-03 Security Monitoring and Alerting
SNow
Reference: LOG-03
Identify and monitor security-related events within applications and the underlying infrastructure. Define and implement a system to generate alerts to responsible stakeholders based on such events and corresponding metrics.
Authority Document
LOG-04 Audit Logs Access and Accountability
SNow
Reference: LOG-04
Restrict audit logs access to authorized personnel and maintain records that provide unique access accountability.
Authority Document
LOG-05 Audit Logs Monitoring and Response
SNow
Reference: LOG-05
Monitor security audit logs to detect activity outside of typical or expected patterns. Establish and follow a defined process to review and take appropriate and timely actions on detected anomalies.
Authority Document
Mapped Processes (1)
LOG-06 Clock Synchronization
SNow
Reference: LOG-06
Use a reliable time source across all relevant information processing systems.
Authority Document
LOG-07 Logging Scope
SNow
Reference: LOG-07
Establish, document and implement which information meta/data system events should be logged. Review and update the scope at least annually or whenever there is a change in the threat environment.
Authority Document
Mapped Processes (1)
LOG-08 Log Records
SNow
Reference: LOG-08
Generate audit records containing relevant security information.
Authority Document
Mapped Processes (1)
LOG-09 Log Protection
SNow
Reference: LOG-09
The information system protects audit records from unauthorized access, modification, and deletion.
Authority Document
LOG-10 Encryption Monitoring and Reporting
SNow
Reference: LOG-10
Establish and maintain a monitoring and internal reporting capability over the operations of cryptographic, encryption and key management policies, processes, procedures, and controls.
Authority Document
LOG-11 Transaction/Activity Logging
SNow
Reference: LOG-11
Log and monitor key lifecycle management events to enable auditing and reporting on usage of cryptographic keys.
Authority Document
LOG-12 Access Control Logs
SNow
Reference: LOG-12
Monitor and log physical access using an auditable access control system.
Authority Document
Mapped Processes (1)
LOG-13 Failures and Anomalies Reporting
SNow
Reference: LOG-13
Define, implement and evaluate processes, procedures and technical measures for the reporting of anomalies and failures of the monitoring system and provide immediate notification to the accountable party.
Authority Document
Mapped Processes (2)
SEF-01 Security Incident Management Policy and Procedures
SNow
Reference: SEF-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Security Incident Management, E-Discovery, and Cloud Forensics. Review and update the policies and procedures at least annually.
Authority Document
SEF-02 Service Management Policy and Procedures
SNow
Reference: SEF-02
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the timely management of security incidents. Review and update the policies and procedures at least annually.
Authority Document
SEF-03 Incident Response Plans
SNow
Reference: SEF-03
Establish, document, approve, communicate, apply, evaluate and maintain a security incident response plan, which includes but is not limited to: relevant internal departments, impacted CSCs, and other business critical relationships (such as supply-chain) that may be impacted.'
Authority Document
Mapped Processes (2)
SEF-04 Incident Response Testing
SNow
Reference: SEF-04
Test and update as necessary incident response plans at planned intervals or upon significant organizational or environmental changes for effectiveness.
Authority Document
SEF-05 Incident Response Metrics
SNow
Reference: SEF-05
Establish and monitor information security incident metrics.
Authority Document
Mapped Processes (2)
SEF-06 Event Triage Processes
SNow
Reference: SEF-06
Define, implement and evaluate processes, procedures and technical measures supporting business processes to triage security-related events.
Authority Document
Mapped Processes (2)
SEF-07 Security Breach Notification
SNow
Reference: SEF-07
Define and implement, processes, procedures and technical measures for security breach notifications. Report security breaches and assumed security breaches including any relevant supply chain breaches, as per applicable SLAs, laws and regulations.
Authority Document
Mapped Processes (2)
SEF-08 Points of Contact Maintenance
SNow
Reference: SEF-08
Maintain points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities.
Authority Document
STA-01 SSRM Policy and Procedures
SNow
Reference: STA-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the application of the Shared Security Responsibility Model (SSRM) within the organization. Review and update the policies and procedures at least annually.
Authority Document
STA-02 SSRM Supply Chain
SNow
Reference: STA-02
Apply, document, implement and manage the SSRM throughout the supply chain for the cloud service offering.
Authority Document
STA-03 SSRM Guidance
SNow
Reference: STA-03
Provide SSRM Guidance to the CSC detailing information about the SSRM applicability throughout the supply chain.
Authority Document
STA-04 SSRM Control Ownership
SNow
Reference: STA-04
Delineate the shared ownership and applicability of all CSA CCM controls according to the SSRM for the cloud service offering.
Authority Document
STA-05 SSRM Documentation Review
SNow
Reference: STA-05
Review and validate SSRM documentation for all cloud services offerings the organization uses.
Authority Document
STA-06 SSRM Control Implementation
SNow
Reference: STA-06
Implement, operate, and audit or assess the portions of the SSRM which the organization is responsible for.
Authority Document
STA-07 Supply Chain Inventory
SNow
Reference: STA-07
Develop and maintain an inventory of all supply chain relationships.
Authority Document
Mapped Processes (1)
STA-08 Supply Chain Risk Management
SNow
Reference: STA-08
CSPs periodically review risk factors associated with all organizations within their supply chain.
Authority Document
Mapped Processes (1)
STA-09 Primary Service and Contractual Agreement
SNow
Reference: STA-09
Service agreements between CSPs and CSCs (tenants) must incorporate at least the following mutually-agreed upon provisions and/or terms:
Scope, characteristics and location of business relationship and services offered
Information security requirements (including SSRM)
Change management proces
Authority Document
Mapped Processes (1)
STA-10 Supply Chain Agreement Review
SNow
Reference: STA-10
Review supply chain agreements between CSPs and CSCs at least annually.
Authority Document
Mapped Processes (1)
STA-11 Internal Compliance Testing
SNow
Reference: STA-11
Define and implement a process for conducting internal assessments to confirm conformance and effectiveness of standards, policies, procedures, and service level agreement activities at least annually.
Authority Document
Mapped Processes (2)
STA-12 Supply Chain Service Agreement Compliance
SNow
Reference: STA-12
Implement policies requiring all CSPs throughout the supply chain to comply with information security, confidentiality, access control, privacy, audit, personnel policy and service level requirements and standards.
Authority Document
Mapped Processes (1)
STA-13 Supply Chain Governance Review
SNow
Reference: STA-13
Periodically review the organization's supply chain partners' IT governance policies and procedures.
Authority Document
Mapped Processes (1)
STA-14 Supply Chain Data Security Assessment
SNow
Reference: STA-14
Define and implement a process for conducting security assessments periodically for all organizations within the supply chain.
Authority Document
Mapped Processes (1)
TVM-01 Threat and Vulnerability Management Policy and Procedures
SNow
Reference: TVM-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to identify, report and prioritize the remediation of vulnerabilities, in order to protect systems against vulnerability exploitation. Review and update the policies and procedures at least annually.
Authority Document
TVM-02 Malware Protection Policy and Procedures
SNow
Reference: TVM-02
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect against malware on managed assets. Review and update the policies and procedures at least annually.
Authority Document
TVM-03 Vulnerability Remediation Schedule
SNow
Reference: TVM-03
Define, implement and evaluate processes, procedures and technical measures to enable both scheduled and emergency responses to vulnerability identifications, based on the identified risk.
Authority Document
Mapped Processes (2)
TVM-04 Detection Updates
SNow
Reference: TVM-04
Define, implement and evaluate processes, procedures and technical measures to update detection tools, threat signatures, and indicators of compromise on a weekly, or more frequent basis.
Authority Document
TVM-05 External Library Vulnerabilities
SNow
Reference: TVM-05
Define, implement and evaluate processes, procedures and technical measures to identify updates for applications which use third party or open source libraries according to the organization's vulnerability management policy.
Authority Document
Mapped Processes (1)
TVM-06 Penetration Testing
SNow
Reference: TVM-06
Define, implement and evaluate processes, procedures and technical measures for the periodic performance of penetration testing by independent third parties.
Authority Document
TVM-07 Vulnerability Identification
SNow
Reference: TVM-07
Define, implement and evaluate processes, procedures and technical measures for the detection of vulnerabilities on organizationally managed assets at least monthly.
Authority Document
TVM-08 Vulnerability Prioritization
SNow
Reference: TVM-08
Use a risk-based model for effective prioritization of vulnerability remediation using an industry recognized framework.
Authority Document
Mapped Processes (1)
TVM-09 Vulnerability Management Reporting
SNow
Reference: TVM-09
Define and implement a process for tracking and reporting vulnerability identification and remediation activities that includes stakeholder notification.
Authority Document
Mapped Processes (1)
TVM-10 Vulnerability Management Metrics
SNow
Reference: TVM-10
Establish, monitor and report metrics for vulnerability identification and remediation at defined intervals.
Authority Document
UEM-01 Endpoint Devices Policy and Procedures
SNow
Reference: UEM-01
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for all endpoints. Review and update the policies and procedures at least annually.
Authority Document
UEM-02 Application and Service Approval
SNow
Reference: UEM-02
Define, document, apply and evaluate a list of approved services, applications and sources of applications (stores) acceptable for use by endpoints when accessing or storing organization-managed data.
Authority Document
UEM-03 Compatibility
SNow
Reference: UEM-03
Define and implement a process for the validation of the endpoint device's compatibility with operating systems and applications.
Authority Document
UEM-04 Endpoint Inventory
SNow
Reference: UEM-04
Maintain an inventory of all endpoints used to store and access company data.
Authority Document
Mapped Processes (1)
UEM-05 Endpoint Management
SNow
Reference: UEM-05
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
Authority Document
UEM-06 Automatic Lock Screen
SNow
Reference: UEM-06
Configure all relevant interactive-use endpoints to require an automatic lock screen.
Authority Document
UEM-07 Operating Systems
SNow
Reference: UEM-07
Manage changes to endpoint operating systems, patch levels, and/or applications through the company's change management processes.
Authority Document
Mapped Processes (1)
UEM-08 Storage Encryption
SNow
Reference: UEM-08
Protect information from unauthorized disclosure on managed endpoint devices with storage encryption.
Authority Document
UEM-09 Anti-Malware Detection and Prevention
SNow
Reference: UEM-09
Configure managed endpoints with anti-malware detection and prevention technology and services.
Authority Document
UEM-10 Software Firewall
SNow
Reference: UEM-10
Configure managed endpoints with properly configured software firewalls.
Authority Document
UEM-11 Data Loss Prevention
SNow
Reference: UEM-11
Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.
Authority Document
UEM-12 Remote Locate
SNow
Reference: UEM-12
Enable remote geo-location capabilities for all managed mobile endpoints.
Authority Document
UEM-13 Remote Wipe
SNow
Reference: UEM-13
Define, implement and evaluate processes, procedures and technical measures to enable the deletion of company data remotely on managed endpoint devices.
Authority Document
UEM-14 Third-Party Endpoint Security Posture
SNow
Reference: UEM-14
Define, implement and evaluate processes, procedures and technical and/or contractual measures to maintain proper security of third-party endpoints with access to organizational assets.
Authority Document
Mapped Processes (1)