1
00:00:06,510 --> 00:00:07,800
- [Instructor] So in this segment,

2
00:00:07,800 --> 00:00:10,560
we're gonna take a closer look at CSA,

3
00:00:10,560 --> 00:00:12,540
that's the Cloud Security Alliance,

4
00:00:12,540 --> 00:00:16,410
Cloud Controls Matrix known as the CCM.

5
00:00:16,410 --> 00:00:17,550
Now, to do that,

6
00:00:17,550 --> 00:00:22,550
we're gonna go out to
cloudsecurityalliance.org.

7
00:00:22,710 --> 00:00:26,850
Now there are several resources
that are worth discovering.

8
00:00:26,850 --> 00:00:31,410
But I really wanna focus in
on the Cloud Controls Matrix.

9
00:00:31,410 --> 00:00:34,230
So I'm coming up here to
the top to STAR program

10
00:00:34,230 --> 00:00:37,683
and I'm going to the Cloud
Controls Matrix or CCM.

11
00:00:41,400 --> 00:00:43,710
Now, the CSA, Cloud Controls Matrix,

12
00:00:43,710 --> 00:00:47,640
is a cybersecurity control
framework for cloud computing

13
00:00:47,640 --> 00:00:49,560
and it's really awesome.

14
00:00:49,560 --> 00:00:53,640
It's composed of 197 control
objectives that are structured

15
00:00:53,640 --> 00:00:58,640
into 17 domains covering all
aspects of cloud technology.

16
00:00:59,280 --> 00:01:02,070
You can use it for a systematic assessment

17
00:01:02,070 --> 00:01:03,990
of your cloud implementation,

18
00:01:03,990 --> 00:01:05,880
as well as it provides guidance

19
00:01:05,880 --> 00:01:08,520
on which security controls
should be implemented

20
00:01:08,520 --> 00:01:11,760
by which actor within
the cloud supply chain.

21
00:01:11,760 --> 00:01:14,790
Meaning the provider or the user.

22
00:01:14,790 --> 00:01:18,120
The controls framework
is aligned with the CSA

23
00:01:18,120 --> 00:01:20,220
Security Guidance for Cloud Computing

24
00:01:20,220 --> 00:01:23,400
and is absolutely considered
the defacto standard

25
00:01:23,400 --> 00:01:26,730
for cloud security
assurance and compliance.

26
00:01:26,730 --> 00:01:29,670
Now, the CCM has recently been updated

27
00:01:29,670 --> 00:01:33,960
and it includes controls,
mapping, a questionnaire,

28
00:01:33,960 --> 00:01:38,220
implementation guidelines,
auditing guidelines, metrics,

29
00:01:38,220 --> 00:01:40,470
and if you're doing automation,

30
00:01:40,470 --> 00:01:42,933
it has machine readable files.

31
00:01:45,090 --> 00:01:48,030
So how can you use the CCM and the CAIQ?

32
00:01:48,030 --> 00:01:49,530
That's the questionnaire.

33
00:01:49,530 --> 00:01:53,070
Well first of all, you can
use it to document controls

34
00:01:53,070 --> 00:01:57,060
for multiple standards and
regulations in one place.

35
00:01:57,060 --> 00:01:59,490
The controls in the CCM are mapped

36
00:01:59,490 --> 00:02:03,120
against industry accepted
security standard regulations

37
00:02:03,120 --> 00:02:06,300
and control frameworks,
including but not limited to,

38
00:02:06,300 --> 00:02:10,817
ISO, NIST, the German BSI-CS,

39
00:02:10,817 --> 00:02:15,030
PCI DSS, Payment Card Industry
Data Security Standard.

40
00:02:15,030 --> 00:02:18,090
ISACA COBIT, NERC, FedRamp,

41
00:02:18,090 --> 00:02:21,120
CIS, and many others.

42
00:02:21,120 --> 00:02:23,160
Now you can use it to also clarify

43
00:02:23,160 --> 00:02:24,840
the shared responsibility model

44
00:02:24,840 --> 00:02:26,670
that we talked about in the lesson.

45
00:02:26,670 --> 00:02:30,300
The CCM defines the attributes
of the responsibility

46
00:02:30,300 --> 00:02:33,570
between the cloud service
provider and the customer.

47
00:02:33,570 --> 00:02:37,110
And it also helps define
the organizational relevance

48
00:02:37,110 --> 00:02:39,870
of each control based on the work done

49
00:02:39,870 --> 00:02:43,323
by the CSA Enterprise
Architecture Working Group.

50
00:02:45,180 --> 00:02:50,180
Now, you can also use this to
assess your service providers.

51
00:02:50,340 --> 00:02:51,810
There is a questionnaire

52
00:02:51,810 --> 00:02:54,360
that's called the CAIQ questionnaire.

53
00:02:54,360 --> 00:02:56,520
In version four, the
version we're looking at

54
00:02:56,520 --> 00:03:00,180
includes a consensus assessment
initiative questionnaire

55
00:03:00,180 --> 00:03:03,690
known as a CAIQ in the same document.

56
00:03:03,690 --> 00:03:07,770
Now, the CAIQ provides a
set of yes or no questions

57
00:03:07,770 --> 00:03:10,830
that can be used to assess
a cloud service provider

58
00:03:10,830 --> 00:03:12,360
and it eliminates the needs

59
00:03:12,360 --> 00:03:14,550
to have multiple different questionnaires

60
00:03:14,550 --> 00:03:16,563
for individual cloud consumers.

61
00:03:17,640 --> 00:03:19,260
The other thing I want
you to take a look at

62
00:03:19,260 --> 00:03:21,810
when you're out at the
site is the STAR program.

63
00:03:21,810 --> 00:03:23,940
Now, there are two levels
to the STAR program,

64
00:03:23,940 --> 00:03:25,620
level one and level two.

65
00:03:25,620 --> 00:03:29,100
And what the STAR program
does is it tells you

66
00:03:29,100 --> 00:03:33,000
how closely aligned with the
security controls, right,

67
00:03:33,000 --> 00:03:35,160
the various cloud vendors are.

68
00:03:35,160 --> 00:03:37,440
So let's take a look at STAR level two.

69
00:03:37,440 --> 00:03:39,873
We're gonna look at view
companies at level two.

70
00:03:41,130 --> 00:03:44,940
This is our Security Trust
Assurance and Risk Registry.

71
00:03:44,940 --> 00:03:47,400
That's what the STAR stands for.

72
00:03:47,400 --> 00:03:50,130
I can scroll down and
look at various vendors.

73
00:03:50,130 --> 00:03:52,053
Let's say I wanna look at Accenture.

74
00:03:52,920 --> 00:03:54,300
I can view their listing.

75
00:03:54,300 --> 00:03:56,130
I can see that they are a STAR level one

76
00:03:56,130 --> 00:03:58,500
which is a self-assessment.

77
00:03:58,500 --> 00:04:02,700
A STAR level two because
they have a certification.

78
00:04:02,700 --> 00:04:04,830
In this case, they have earned

79
00:04:04,830 --> 00:04:09,540
the ISO 27001 2013 certification

80
00:04:09,540 --> 00:04:11,490
and they've also been awarded

81
00:04:11,490 --> 00:04:14,790
the Trusted Cloud Provider by CSA.

82
00:04:14,790 --> 00:04:16,290
And if I wanna view the listing,

83
00:04:16,290 --> 00:04:18,270
I can go into View Listing.

84
00:04:18,270 --> 00:04:21,000
I can see that they have Accenture itself

85
00:04:21,000 --> 00:04:24,393
and then private cloud, and
I can go further in and look.

86
00:04:26,370 --> 00:04:28,200
I can see their self-assessment.

87
00:04:28,200 --> 00:04:30,660
I could download the
self-assessment that they did,

88
00:04:30,660 --> 00:04:33,243
and I could take a look
at their certification.

89
00:04:34,440 --> 00:04:36,067
So a really awesome way to say,

90
00:04:36,067 --> 00:04:38,490
"Okay I wanna see how the cloud providers

91
00:04:38,490 --> 00:04:39,930
that I'm thinking of doing business with."

92
00:04:39,930 --> 00:04:41,910
This would be during your
due diligence period.

93
00:04:41,910 --> 00:04:44,640
You know, how well do
they meet this criteria?

94
00:04:44,640 --> 00:04:47,370
So you can use this for
assessing your providers

95
00:04:47,370 --> 00:04:49,200
as well as in bringing down

96
00:04:49,200 --> 00:04:51,300
those cloud control matrix controls

97
00:04:51,300 --> 00:04:53,040
to help you make sure that you have

98
00:04:53,040 --> 00:04:57,123
a really, really secure and
awesome cloud environment.

99
00:04:57,990 --> 00:05:00,273
And that, my friends, is a closer look.
