Cloud Security Alliance CCM Controls Implementation Training Course

5 days Cloud Computing Certificate on completion
Course codeSD-CC-026
Duration5 days
LevelIntermediate
CategoryCloud Computing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Cloud security programmes often contain sound policies but lack a consistent way to translate cloud risks, provider assurances and technical safeguards into auditable control requirements. Teams must answer practical questions: which CCM controls apply to a SaaS, PaaS or IaaS service; how should shared responsibility affect ownership; what evidence proves implementation; and where do supplier claims leave material gaps? This course provides a structured method for using the Cloud Security Alliance Cloud Controls Matrix (CCM) to build defensible cloud control baselines and assessment records.

Participants work through CCM v4 domains, control specifications, implementation guidance and mappings to related frameworks. They learn to scope an assessment, identify applicable controls, assign control owners, distinguish customer and cloud service provider responsibilities, gather evidence, rate control maturity and document exceptions. The course also covers using the Consensus Assessments Initiative Questionnaire (CAIQ), interpreting CSA STAR information, mapping CCM controls to ISO/IEC 27001 requirements, and prioritising remediation through a risk-based control improvement plan.

Teaching combines instructor-led control analysis with guided workshops based on a cloud service onboarding scenario. Participants build a CCM-based control applicability matrix, evidence request list, shared-responsibility assignment model, gap register and remediation roadmap for a selected cloud workload. They leave with a reusable implementation pack that can be adapted for supplier due diligence, cloud migration governance, internal assurance or audit preparation.

The course is designed for security, risk, compliance and cloud professionals who already work with cloud services and need a repeatable control framework rather than a high-level introduction to cloud security.

Course objectives

By the end of this course, participants will be able to:

  • Scope a cloud workload assessment using CCM v4 domains, control specifications and service-model context
  • Build a CCM control applicability matrix for SaaS, PaaS and IaaS environments
  • Assign customer, provider and shared control ownership through a shared-responsibility model
  • Map CCM controls to ISO/IEC 27001:2022 requirements and existing organisational policies
  • Create evidence requests using CCM implementation guidance and CAIQ control questions
  • Assess control design and operating effectiveness using documented evidence and maturity criteria
  • Document cloud control gaps, exceptions and risk treatment actions in a remediation register
  • Produce a phased CCM implementation roadmap with owners, priorities and review measures

Benefits of attending

For you

  • Gain a repeatable method for converting CCM requirements into workload-specific control baselines
  • Build credibility when challenging cloud supplier assurances with CAIQ and evidence-based questions
  • Strengthen capability to lead cloud security assessments across SaaS, PaaS and IaaS services
  • Create audit-ready control mappings, ownership records and remediation documentation
  • Develop a portfolio-ready CCM implementation pack applicable to cloud security, GRC and assurance roles

For your organisation

  • Establish a consistent CCM-based control baseline for cloud onboarding and ongoing assurance
  • Reduce unmanaged shared-responsibility gaps between internal teams and cloud service providers
  • Improve supplier due diligence through structured CAIQ, STAR and evidence-review practices
  • Produce clearer remediation priorities by linking control deficiencies to owners, risks and deadlines
  • Accelerate audit and compliance preparation with traceable control mappings and evidence requests

Target competencies

CCM control scopingShared responsibility mappingCloud evidence assessmentCAIQ supplier reviewControl gap analysisRemediation roadmap design

Who should attend

  • Cloud Security Architects — who need to turn cloud architecture risks into implemented and testable controls
  • Information Security Managers — who need a common control baseline across cloud platforms and suppliers
  • GRC and Compliance Managers — who must map cloud controls to assurance, audit and regulatory obligations
  • Third-Party Risk Managers — who assess cloud provider responses, CAIQs and supplier evidence
  • Cloud Platform Engineers — who implement technical safeguards and need clear accountability for CCM controls
  • Internal Auditors — who need to test cloud control design, evidence and ownership against a recognised framework

Requirements and prerequisites

Participants should understand core information security concepts such as access control, encryption, logging, vulnerability management, incident response and risk assessment. Familiarity with at least one cloud service model (SaaS, PaaS or IaaS) and practical exposure to a public cloud provider, cloud supplier review or security governance process is expected. Participants should be comfortable reading policy, architecture and audit-evidence documents and using spreadsheets. Prior knowledge of the CSA CCM, CAIQ or CSA STAR is not required, and no programming, cloud console administration or formal audit qualification is needed.

Training methodology

The instructor introduces each CCM method using annotated control extracts, cloud architecture examples and assessment templates before participants apply it in facilitated workshops. Small groups assess a fictional organisation moving regulated workloads to a cloud provider, review CAIQ-style responses, assign shared responsibilities and test evidence against selected CCM controls. Daily outputs feed a single implementation pack. On day five, participants consolidate their applicability matrix, gap register and remediation roadmap, then receive peer and instructor feedback on how to adapt the materials to their own cloud environment.

Course outline

Day 1: CCM foundations and assessment scoping

  • CSA Cloud Controls Matrix v4 structure and control domains
  • Cloud service models and deployment models in control scoping
  • Shared-responsibility principles for customer and provider controls
  • CCM control specifications and implementation guidance
  • Control applicability criteria for cloud workloads
  • Cloud asset, data and service dependency identification
  • Assessment charter, stakeholders and evidence boundaries

Workshop: Participants scope a cloud-hosted business service and produce an assessment charter with service model, data types, stakeholders and initial CCM domains.

Day 2: Control applicability and framework mapping

  • Building a CCM control applicability matrix
  • Selecting controls for SaaS, PaaS and IaaS workloads
  • Control ownership using RACI and shared-responsibility assignments
  • Mapping CCM controls to ISO/IEC 27001:2022 Annex A
  • Aligning CCM requirements with internal security policies
  • Documenting inherited, provider-managed and customer-operated controls
  • Defining control implementation status and rationale

Workshop: Participants create a populated CCM applicability matrix and ownership model for a selected SaaS or IaaS implementation.

Day 3: Supplier assurance and evidence evaluation

  • CSA CAIQ v4 structure and use in supplier assessments
  • CSA STAR Registry assurance information and limitations
  • Evidence types for cloud control implementation
  • Reviewing policies, configurations, reports and attestations
  • Testing control design versus operating effectiveness
  • Evidence sufficiency, recency and traceability criteria
  • Supplier clarification questions and evidence request lists

Workshop: Participants analyse a supplier assurance pack, identify insufficient evidence and produce a targeted CAIQ-based evidence request list.

Day 4: Gap assessment and remediation planning

  • CCM-based control gap identification
  • Risk rating criteria for cloud control deficiencies
  • Recording compensating controls and residual risk
  • Exception management and risk acceptance documentation
  • Remediation action design and accountable ownership
  • Prioritising improvements by business impact and dependency
  • Control metrics and assurance review cadence

Workshop: Participants convert assessment findings into a gap register with risk ratings, compensating controls, owners, target dates and escalation decisions.

Day 5: Implementing and governing the CCM programme

  • Designing a phased CCM implementation roadmap
  • Embedding CCM into cloud onboarding workflows
  • Using CCM in architecture review and change governance
  • Integrating supplier reassessment and contract controls
  • Preparing audit-ready control narratives and evidence trails
  • Reporting cloud control posture to management
  • Continuous improvement through control review cycles

Workshop: Participants assemble and present a CCM implementation pack containing an applicability matrix, evidence plan, gap register and 90-day remediation roadmap.

Tools & standards covered

CSA Cloud Controls Matrix (CCM) v4, CSA Consensus Assessments Initiative Questionnaire (CAIQ) v4, CSA STAR Registry, ISO/IEC 27001:2022

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No prior CCM or CAIQ experience is required. You should already understand basic security controls and have some familiarity with cloud services, supplier assurance or security governance.

No cloud tenant access is needed. Exercises use CCM extracts, CAIQ-style responses, architecture scenarios and spreadsheet-based templates rather than live configuration work.

It suits professionals responsible for cloud security architecture, GRC, compliance, internal audit, third-party risk or cloud platform governance. It is particularly useful when an organisation needs a repeatable way to assess cloud services against recognised controls.

General cloud security training commonly focuses on threats, architecture patterns or provider-specific technical configuration. This course focuses on operationalising the CSA CCM: scoping controls, assigning responsibility, requesting evidence, assessing gaps and planning remediation.

You can use the implementation pack to assess a planned cloud migration, review a SaaS supplier, establish a cloud control baseline or prepare evidence for an internal audit. The templates are designed to be adapted to your organisation's policies and risk methodology.

You leave with a completed CCM control applicability matrix, shared-responsibility assignment model, evidence request list, gap register and phased remediation roadmap. These outputs are produced against the course scenario and can be reused as working templates.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cloud Computing

5 Days Certificate

Cloud Networking Fundamentals for Infrastructure Teams Training Course

Infrastructure teams increasingly support applications spread across cloud accounts, regions, managed services and on-premises environments.…

5 Days Certificate

Google Cloud Platform Administration for IT Teams Training Course

Google Cloud administrators must turn project requests into controlled, supportable environments without slowing delivery. That means design…

5 Days Certificate

AWS Cloud Infrastructure Management Training Course

AWS infrastructure teams must provision secure, reliable environments while controlling spend, responding to incidents and meeting internal …

5 Days Certificate

Cloud Governance Skills for IT Managers Training Course

IT managers are expected to enable teams to use cloud services quickly while retaining control of spend, security, data handling and operati…