Skip to main content
Image coming soon

CSA Cloud Controls Matrix CCM Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
CSA Cloud Controls Matrix · CCM v4 · Evidence & Implementation Kit
Secure your cloud to the CSA Cloud Controls Matrix, without mapping 17 domains to evidence yourself.
Every CCM domain handed to you as adopt-ready controls with real control IDs, from identity and encryption to the shared security responsibility model, with the evidence an assessor examines.
Cloud-secure in a weekend, not a quarter.

Here is the honest situation. The CSA Cloud Controls Matrix is the de facto standard for cloud security, 197 control objectives across 17 domains, and it underpins the CSA STAR program. Its defining feature is the shared security responsibility model: some controls are the provider's, some are yours, and the ones that fall in the gap are where breaches happen. Mapping all 17 domains, splitting responsibility with your provider, and assembling the evidence is weeks of work, and a control everyone assumed the other party owned is exactly where cloud responsibility falls through.

This Kit removes that build. It is every CCM domain written as adopt-ready controls with real control IDs you personalize in a weekend, with the evidence an assessor examines.

What you get, the moment you buy

34
All 17 domains, adopt-ready. Every CCM domain, from audit and identity through encryption, data security and the shared responsibility model, written as adopt-ready controls with real CCM control IDs, so you personalize and apply them.
34
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus where cloud responsibility falls through the gap, so you close it first.
1
Cloud Controls Matrix, pre-built. Every control in a working spreadsheet, ready to record provider-versus-customer responsibility, status and evidence location.
1
Gap & Readiness Assessment. Score each control and the workbook returns your cloud security readiness as a single percentage, and exactly what to fix next.

Grounded in the CSA Cloud Controls Matrix v4 across all 17 domains, with real control IDs, and the Shared Security Responsibility Model, cryptography and key management, data security and identity called out. Editable Word and Excel files.

The shared responsibility model is where breaches hide
Most cloud breaches are not a broken control, they are a control nobody owned because each party assumed the other did. The CCM's shared responsibility model makes ownership explicit. This Kit builds that allocation into every control, so nothing falls through the gap between you and your provider.

What one control looks like

This is the shared security responsibility model policy, where cloud ownership is decided. All 34 are built to this depth.

STA-01 SSRM Policy and Procedures SHARED RESPONSIBILITY
Implement this control

[Organization] shall establish, document, approve, communicate, apply, evaluate, and maintain policies and procedures for the shared security responsibility model, review them at least annually, and define how responsibility for each control area is allocated between the cloud service provider, [Organization], and the customer so that no control area is left unowned across the service stack.

Cloud note.

The keystone control of the STA domain. Every other SSRM control operationalizes this allocation.

Evidence an assessor examines
  • Shared security responsibility model policy with review record
  • Responsibility allocation matrix across control areas
  • Communication of the model to customers and internal teams
  • Evidence the model is referenced during onboarding
Common finding they raise: No documented responsibility model exists, so provider, organization, and customer each assume another party owns a control and gaps go unnoticed until an incident.

Why this is not another template pack

  • The evidence is the point. A cloud control you cannot evidence is a gap. This tells you exactly what an assessor examines and where responsibility falls through, for every domain.
  • Real control IDs and the SSRM. Every control uses its real CCM identifier, and the shared responsibility model is built in, so it maps straight to a CSA STAR assessment.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The CCM maps onto ISO 27001, SOC 2 and NIST, so this work feeds your wider security and assurance program.

Who buys this

Organizations securing cloud services or pursuing CSA STAR, the cloud security leads who own it, and consultants preparing an assessment. Whether it is a first cloud security program or a STAR submission, you save weeks and walk in with the domains and evidence structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 17 domains
✓  A completed cloud controls matrix
✓  The evidence an assessor examines
✓  Your provider-versus-customer responsibility split
✓  A readiness percentage and a fix list
✓  The responsibility gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Does it cover all 17 domains? Yes, with representative controls using real CCM control IDs across every domain, from audit to universal endpoint management.

Does it support CSA STAR? Yes. The CCM is the control set behind CSA STAR, and the shared responsibility allocation supports a STAR self-assessment.

Does it cover the shared responsibility model? Yes. The Shared Security Responsibility Model is built into the supply-chain domain and threaded through every control.

What if it is not for me? A 30-day money-back guarantee.

Do not let a control fall through the cloud responsibility gap.
Every CCM domain is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and secure your cloud this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com