Control framework by the Cloud Security Alliance for cloud security.
The Cloud Controls Matrix (CCM) is a catalogue of security controls maintained by the Cloud Security Alliance, specifically tailored to cloud services. It is structured into domains such as access control, encryption, governance, and supply chain security, and can be mapped to common standards such as ISO 27001. Providers use the CCM to assess their cloud security in a structured manner; the associated CAIQ transforms it into a concrete questionnaire. The CCM is a recognised reference framework within the CSA STAR programme.
For cloud and SaaS providers, the CCM is a useful reference framework, as many client inquiries are oriented around its domains. Clients are effectively asking about the same controls, just in different formats. Without structured storage, the answers still have to be gathered anew each time. Those who document their security measures once along the lines of the CCM can reuse them for the CAIQ and client-specific questionnaires.
With Tendry, you use your CCM-aligned security evidence for all client questionnaires from a single verified source. This allows you to answer cloud security questions thoroughly once, rather than starting from scratch each time.