01The CCM: 17 domains, 207 controls
CCM v4.1 organizes cloud security into 17 domains with a total of 207 control objectives — including Audit & Assurance, Application & Interface Security, Cryptography and Key Management, Identity & Access Management, Logging & Monitoring, and Supply Chain Management. The domain structure deliberately aligns with established frameworks such as ISO 27001:2022 so that existing knowledge can be put to use. For each control, the matrix additionally indicates its applicability to the IaaS, PaaS, and SaaS service models.
02CAIQ: 283 questions for vendor assessment
The Consensus Assessment Initiative Questionnaire (CAIQ) translates the CCM controls into 283 yes/no questions that cloud customers and auditors can use to systematically examine the security posture of a cloud service provider. It serves as a standardized instrument for provider assessment — both before contracting and in ongoing supplier management. The v4.1 structure also includes dedicated columns for documenting responsibilities under the Shared Security Responsibility Model.
03Shared Security Responsibility Model (SSRM)
The CCM assigns each control a responsibility under the Shared Security Responsibility Model: CSP-Owned, CSC-Owned, Shared (Independent), or Shared (Dependent). The framework thereby answers the central question of who is responsible for what in a cloud project. Responsibility handovers between provider and customer become transparent at the level of individual controls — and can be cleanly anchored in contracts as well as in operations.
04STAR program and STAR Registry
The CAIQ is the basis for STAR Level 1: cloud providers submit their completed security questionnaire to the public CSA STAR Registry, creating transparency about their control landscape. STAR Continuous extends the approach with continuous assessment — with the goal of enabling compliance statements on a monthly, daily, or even hourly basis. The CCM is thus the foundation on which CSPs are compared and evaluated.
05Implementation and standard mappings
The CCM Implementation Guidelines (v2.1) provide implementation recommendations for each control specification along the SSRM role allocation — deliberately without rigid how-to prescriptions, since implementation depends on architecture, technology, and risk profile. Mappings link the CCM to ISO/IEC 27001/27002/27017/27018, AICPA TSC, CIS Controls, NIST CSF, NIST 800-53, and PCI DSS. This makes it possible to identify gaps and overlaps between frameworks and to reduce duplicated compliance effort.
06Continuous audit metrics
The Continuous Audit Metrics Catalog (v1.1) defines 34 cloud security metrics that tie directly into CCM controls and can largely be measured automatically — the foundation for continuous auditing instead of annual point-in-time assessments. The terminology follows ISO/IEC 19086-1, the standard framework for cloud SLAs. The accompanying Code of Practice describes eight requirements for viable key metrics, from strategic alignment and clear RACI responsibility to tamper resistance.