GRC Blog
GRC Blog
- Details
- Written by: Robin Basham
- Parent Category: GRC Blog
- Category: Bay Area News & Events
April 2021 Webinar 5: Transitioning to CCM 4.0, Do It Now, Map It Right
Summary:
CCM has released version 4.0 with a reasonable runway to transition. This topic explains why organizations who are CSTAR Centric and wish to align ISO27001 with Cloud, Privacy and Data, FedRAMP 800-53B/NIST 800-53r5, NIST 171 plus the new 172, and SOC 2, really need the newer version and shouldn’t wait to start cross mapping their regulatory requirements.
Outline
What Major Regulations Completely Changed over the last 24 months?
Why update everything now? (What’s the domino effect of waiting?)
Which are the key new requirements, such as Cryptographic Controls and new legal considerations for IOT?
How are DevOps, SecOps better represented in the new standards? (NIST/CCM)
Who and where are the working groups we can interact with to accomplish new mapping?
What are the common pitfalls in notation for ISO and NIST Standards? How can these be overcome?
One Detail Breakout: Mapping the 21 CCM (CEK) Cryptography Controls to
* NIST 800-53 r5
* NIST 800 171 r2
* NIST 800 172 Enhanced Security Requirements for Protecting Controlled Unclassified Information; A Supplement to NIST Special Publication 800-171
* ISO/IEC 27001:2013 €, as implemented with
* ISO/IEC 27002:2013 €, including certification for Cloud, Privacy, and PII Processors
* ISO/IEC 27017:2015 € 27002 for cloud services
* ISO/IEC 27018:2019 € Information technology — Security techniques — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
* ISO/IEC 27701:2019 € Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines
* TSP 100—2017 Trust Services Criteria for SOC 2
Pitfalls in Mapping Cloud Controls Matrix V4 Presented to ISACA April 28, 2021
Agenda:
6:00 - 6:05 - Welcome and Introduction
6:05 - 6:45 - Session: Transitioning to CCM 4.0, Do It Now, Map It Right
6:45 - 6:55 - Q & A
6:55 - 7:00 – Wrap-up
- Hits: 278

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics