Cloud Security Alliance CCM Controls Implementation Training Course
| Course code | SD-CC-026 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Cloud Computing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Cloud security programmes often contain sound policies but lack a consistent way to translate cloud risks, provider assurances and technical safeguards into auditable control requirements. Teams must answer practical questions: which CCM controls apply to a SaaS, PaaS or IaaS service; how should shared responsibility affect ownership; what evidence proves implementation; and where do supplier claims leave material gaps? This course provides a structured method for using the Cloud Security Alliance Cloud Controls Matrix (CCM) to build defensible cloud control baselines and assessment records.
Participants work through CCM v4 domains, control specifications, implementation guidance and mappings to related frameworks. They learn to scope an assessment, identify applicable controls, assign control owners, distinguish customer and cloud service provider responsibilities, gather evidence, rate control maturity and document exceptions. The course also covers using the Consensus Assessments Initiative Questionnaire (CAIQ), interpreting CSA STAR information, mapping CCM controls to ISO/IEC 27001 requirements, and prioritising remediation through a risk-based control improvement plan.
Teaching combines instructor-led control analysis with guided workshops based on a cloud service onboarding scenario. Participants build a CCM-based control applicability matrix, evidence request list, shared-responsibility assignment model, gap register and remediation roadmap for a selected cloud workload. They leave with a reusable implementation pack that can be adapted for supplier due diligence, cloud migration governance, internal assurance or audit preparation.
The course is designed for security, risk, compliance and cloud professionals who already work with cloud services and need a repeatable control framework rather than a high-level introduction to cloud security.
Course objectives
By the end of this course, participants will be able to:
- Scope a cloud workload assessment using CCM v4 domains, control specifications and service-model context
- Build a CCM control applicability matrix for SaaS, PaaS and IaaS environments
- Assign customer, provider and shared control ownership through a shared-responsibility model
- Map CCM controls to ISO/IEC 27001:2022 requirements and existing organisational policies
- Create evidence requests using CCM implementation guidance and CAIQ control questions
- Assess control design and operating effectiveness using documented evidence and maturity criteria
- Document cloud control gaps, exceptions and risk treatment actions in a remediation register
- Produce a phased CCM implementation roadmap with owners, priorities and review measures
Benefits of attending
For you
- Gain a repeatable method for converting CCM requirements into workload-specific control baselines
- Build credibility when challenging cloud supplier assurances with CAIQ and evidence-based questions
- Strengthen capability to lead cloud security assessments across SaaS, PaaS and IaaS services
- Create audit-ready control mappings, ownership records and remediation documentation
- Develop a portfolio-ready CCM implementation pack applicable to cloud security, GRC and assurance roles
For your organisation
- Establish a consistent CCM-based control baseline for cloud onboarding and ongoing assurance
- Reduce unmanaged shared-responsibility gaps between internal teams and cloud service providers
- Improve supplier due diligence through structured CAIQ, STAR and evidence-review practices
- Produce clearer remediation priorities by linking control deficiencies to owners, risks and deadlines
- Accelerate audit and compliance preparation with traceable control mappings and evidence requests
Target competencies
Who should attend
- Cloud Security Architects — who need to turn cloud architecture risks into implemented and testable controls
- Information Security Managers — who need a common control baseline across cloud platforms and suppliers
- GRC and Compliance Managers — who must map cloud controls to assurance, audit and regulatory obligations
- Third-Party Risk Managers — who assess cloud provider responses, CAIQs and supplier evidence
- Cloud Platform Engineers — who implement technical safeguards and need clear accountability for CCM controls
- Internal Auditors — who need to test cloud control design, evidence and ownership against a recognised framework
Requirements and prerequisites
Participants should understand core information security concepts such as access control, encryption, logging, vulnerability management, incident response and risk assessment. Familiarity with at least one cloud service model (SaaS, PaaS or IaaS) and practical exposure to a public cloud provider, cloud supplier review or security governance process is expected. Participants should be comfortable reading policy, architecture and audit-evidence documents and using spreadsheets. Prior knowledge of the CSA CCM, CAIQ or CSA STAR is not required, and no programming, cloud console administration or formal audit qualification is needed.
Training methodology
The instructor introduces each CCM method using annotated control extracts, cloud architecture examples and assessment templates before participants apply it in facilitated workshops. Small groups assess a fictional organisation moving regulated workloads to a cloud provider, review CAIQ-style responses, assign shared responsibilities and test evidence against selected CCM controls. Daily outputs feed a single implementation pack. On day five, participants consolidate their applicability matrix, gap register and remediation roadmap, then receive peer and instructor feedback on how to adapt the materials to their own cloud environment.
Course outline
Day 1: CCM foundations and assessment scoping
- CSA Cloud Controls Matrix v4 structure and control domains
- Cloud service models and deployment models in control scoping
- Shared-responsibility principles for customer and provider controls
- CCM control specifications and implementation guidance
- Control applicability criteria for cloud workloads
- Cloud asset, data and service dependency identification
- Assessment charter, stakeholders and evidence boundaries
Workshop: Participants scope a cloud-hosted business service and produce an assessment charter with service model, data types, stakeholders and initial CCM domains.
Day 2: Control applicability and framework mapping
- Building a CCM control applicability matrix
- Selecting controls for SaaS, PaaS and IaaS workloads
- Control ownership using RACI and shared-responsibility assignments
- Mapping CCM controls to ISO/IEC 27001:2022 Annex A
- Aligning CCM requirements with internal security policies
- Documenting inherited, provider-managed and customer-operated controls
- Defining control implementation status and rationale
Workshop: Participants create a populated CCM applicability matrix and ownership model for a selected SaaS or IaaS implementation.
Day 3: Supplier assurance and evidence evaluation
- CSA CAIQ v4 structure and use in supplier assessments
- CSA STAR Registry assurance information and limitations
- Evidence types for cloud control implementation
- Reviewing policies, configurations, reports and attestations
- Testing control design versus operating effectiveness
- Evidence sufficiency, recency and traceability criteria
- Supplier clarification questions and evidence request lists
Workshop: Participants analyse a supplier assurance pack, identify insufficient evidence and produce a targeted CAIQ-based evidence request list.
Day 4: Gap assessment and remediation planning
- CCM-based control gap identification
- Risk rating criteria for cloud control deficiencies
- Recording compensating controls and residual risk
- Exception management and risk acceptance documentation
- Remediation action design and accountable ownership
- Prioritising improvements by business impact and dependency
- Control metrics and assurance review cadence
Workshop: Participants convert assessment findings into a gap register with risk ratings, compensating controls, owners, target dates and escalation decisions.
Day 5: Implementing and governing the CCM programme
- Designing a phased CCM implementation roadmap
- Embedding CCM into cloud onboarding workflows
- Using CCM in architecture review and change governance
- Integrating supplier reassessment and contract controls
- Preparing audit-ready control narratives and evidence trails
- Reporting cloud control posture to management
- Continuous improvement through control review cycles
Workshop: Participants assemble and present a CCM implementation pack containing an applicability matrix, evidence plan, gap register and 90-day remediation roadmap.
Tools & standards covered
CSA Cloud Controls Matrix (CCM) v4, CSA Consensus Assessments Initiative Questionnaire (CAIQ) v4, CSA STAR Registry, ISO/IEC 27001:2022
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cloud Computing
Cloud Networking Fundamentals for Infrastructure Teams Training Course
Infrastructure teams increasingly support applications spread across cloud accounts, regions, managed services and on-premises environments.…
Google Cloud Platform Administration for IT Teams Training Course
Google Cloud administrators must turn project requests into controlled, supportable environments without slowing delivery. That means design…
AWS Cloud Infrastructure Management Training Course
AWS infrastructure teams must provision secure, reliable environments while controlling spend, responding to incidents and meeting internal …
Cloud Governance Skills for IT Managers Training Course
IT managers are expected to enable teams to use cloud services quickly while retaining control of spend, security, data handling and operati…