Cloud 101CircleEventsBlog
Register for SECtember.ai, Sept. 9-12, to hear keynotes from leaders at Anthropic, OpenAI, Google, Microsoft and CISA!

Working Group

Cloud Controls Matrix

Along with releasing updated versions of the CCM and CAIQ, this working group provides addendums, control mappings and gap analysis between the CCM and other research releases, industry standards, and regulations to keep it continually up to date.
View Current Projects
Cloud Controls Matrix and CAIQ v4
Cloud Controls Matrix and CAIQ v4

Download

Cloud Controls Matrix
Working Group Overview

Along with releasing updated versions of the CCM and CAIQ, this working group provides addendums, control mappings and gap analysis between the CCM and other research releases, industry standards, and regulations to keep it continually up to date.


CSA is collaborating with IBM in order to align the two frameworks CCM v4 and IBM Cloud Framework. If you're interested in getting involved, please contact Eleftherios Skoutaris, [email protected].


What do we discuss during our meetings? 

During these meetings we typically discuss changes in the industry and collaborate on projects the group is working on.


Drafts & Important Docs


Working Group Leadership

Daniele Catteddu
Daniele Catteddu

Daniele Catteddu

Chief Technology Officer, CSA

Daniele Catteddu is an information security and risk management practitioner, technologies expert and privacy evangelist with over 15 of experience. He worked in several senior roles both in the private and public sector. He is member of various national and international security expert groups and committees on cyber-security and privacy, keynote speaker at several conferences and author of numerous studies and papers on risk management, ...

Read more

Eleftherios Skoutaris
Eleftherios Skoutaris

Eleftherios Skoutaris

Program Manager / Research Analyst, CSA EMEA

Working Group Co-Chairs

David Nickles
David Nickles

David Nickles

AWS

David Nickles is a Global Audit Program Manager for FSI’s at Amazon Web Services (AWS). His work focuses on enabling financial services institutions to move their workloads to the cloud by providing sound guidance for building programs to ensure regulatory, governance, risk, compliance, audit, and security control requirements are met, align to industry best practices, and appropriate due diligence activity is completed. Prior to AWS, David...

Read more

Sean Cordero
Sean Cordero

Sean Cordero

Sean Cordero brings more than 15 years of information security and IT experience to his current role as director, information security at Optiv. Cordero provides executive level advisement for the company’s Fortune 50 clients. Cordero’s prior leadership roles included: President of Cloud Watchmen, CSO for EdFund, CSO for ECMC West, Director of Security and Compliance for Charlotte Russe.

Cordero is a thought-leader and serves as chair...

Read more

Jon-Michael Brook
Jon-Michael Brook

Jon-Michael Brook

Jon-Michael C. Brook is a certified, 25-year practitioner of cybersecurity, cloud, and privacy. He is the principal contributor to certification sites for privacy and cloud security, and has published books on privacy. Jon-Michael received numerous awards and recognition during his time with Raytheon, Northrop Grumman, Symantec, and Starbucks. He holds patents and trade secrets in intrusion detection, GUI design, and semantic data redaction...

Read more

Publications in ReviewOpen Until
Using Asymmetric Cryptography to Help Achieve Zero Trust ObjectivesAug 12, 2024
Don’t Panic! Getting Real About AI GovernanceAug 19, 2024
AI Organizational Responsibilities - Governance, Risk Management, and Cultural AspectsAug 20, 2024
AI in Medical Research: Applications & ConsiderationsAug 20, 2024
View all
Who can join?

Anyone can join a working group, whether you have years of experience or want to just participate as a fly on the wall.

What is the time commitment?

The time commitment for this group varies depending on the project. You can spend a 15 minutes helping review a publication that's nearly finished or help author a publication from start to finish.

Virtual Meetings

Attend our next meeting. You can just listen in to decide if this group is a good for you or you can choose to actively participate. During these calls we discuss current projects, and well as share ideas for new projects. This is a good way to meet the other members of the group. You can view all research meetings here.

Aug

14

Wed, August 14, 6:00pm - 7:00pm
CCMv4 WG
See details
Passcode: 621643

Additional info:

  • Follow up on the latest CCM WG activities in Circle.
  • If having issues finding the CCM WG, please follow the step by step guide to Circle on-boarding here
  • WG call meetings are recorded and made available to the rest of the group. The purpose of the recordings and their use is for the writing of meetings minutes and members in "difficult" time zones only. Please visit the "Data Protection Notice" document, which includes the purposes of use, retention period of audio files, etc.


Eleftherios Skoutaris is inviting you to a scheduled Zoom meeting.

Join Zoom Meeting
https://zoom.us/j/245687063

Meeting ID: 245 687 063
Passcode: 621643

One tap mobile
+16699009128,,245687063# US (San Jose)
+16465588656,,245687063# US (New York)

Dial by your location
        +1 669 900 9128 US (San Jose)
        +1 646 558 8656 US (New York)
Meeting ID: 245 687 063
Find your local number: https://zoom.us/u/ac16Mhvmr3

Aug

28

Wed, August 28, 6:00pm - 7:00pm
CCMv4 WG
See details
Passcode: 621643

Additional info:

  • Follow up on the latest CCM WG activities in Circle.
  • If having issues finding the CCM WG, please follow the step by step guide to Circle on-boarding here
  • WG call meetings are recorded and made available to the rest of the group. The purpose of the recordings and their use is for the writing of meetings minutes and members in "difficult" time zones only. Please visit the "Data Protection Notice" document, which includes the purposes of use, retention period of audio files, etc.


Eleftherios Skoutaris is inviting you to a scheduled Zoom meeting.

Join Zoom Meeting
https://zoom.us/j/245687063

Meeting ID: 245 687 063
Passcode: 621643

One tap mobile
+16699009128,,245687063# US (San Jose)
+16465588656,,245687063# US (New York)

Dial by your location
        +1 669 900 9128 US (San Jose)
        +1 646 558 8656 US (New York)
Meeting ID: 245 687 063
Find your local number: https://zoom.us/u/ac16Mhvmr3

Sep

11

Wed, September 11, 6:00pm - 7:00pm
CCMv4 WG
See details
Passcode: 621643

Additional info:

  • Follow up on the latest CCM WG activities in Circle.
  • If having issues finding the CCM WG, please follow the step by step guide to Circle on-boarding here
  • WG call meetings are recorded and made available to the rest of the group. The purpose of the recordings and their use is for the writing of meetings minutes and members in "difficult" time zones only. Please visit the "Data Protection Notice" document, which includes the purposes of use, retention period of audio files, etc.


Eleftherios Skoutaris is inviting you to a scheduled Zoom meeting.

Join Zoom Meeting
https://zoom.us/j/245687063

Meeting ID: 245 687 063
Passcode: 621643

One tap mobile
+16699009128,,245687063# US (San Jose)
+16465588656,,245687063# US (New York)

Dial by your location
        +1 669 900 9128 US (San Jose)
        +1 646 558 8656 US (New York)
Meeting ID: 245 687 063
Find your local number: https://zoom.us/u/ac16Mhvmr3

Sep

25

Wed, September 25, 6:00pm - 7:00pm
CCMv4 WG
See details
Passcode: 621643

Additional info:

  • Follow up on the latest CCM WG activities in Circle.
  • If having issues finding the CCM WG, please follow the step by step guide to Circle on-boarding here
  • WG call meetings are recorded and made available to the rest of the group. The purpose of the recordings and their use is for the writing of meetings minutes and members in "difficult" time zones only. Please visit the "Data Protection Notice" document, which includes the purposes of use, retention period of audio files, etc.


Eleftherios Skoutaris is inviting you to a scheduled Zoom meeting.

Join Zoom Meeting
https://zoom.us/j/245687063

Meeting ID: 245 687 063
Passcode: 621643

One tap mobile
+16699009128,,245687063# US (San Jose)
+16465588656,,245687063# US (New York)

Dial by your location
        +1 669 900 9128 US (San Jose)
        +1 646 558 8656 US (New York)
Meeting ID: 245 687 063
Find your local number: https://zoom.us/u/ac16Mhvmr3

Open Peer Reviews

Peer reviews allow security professionals from around the world to provide feedback on CSA research before it is published.

Learn how to participate in a peer review here.

Using Asymmetric Cryptography to Help Achieve Zero Trust Objectives

Open Until: 08/12/2024

This paper investigates the convergence of asymmetric cryptography and Zero Trust architecture, exploring the utilization o...

Don’t Panic! Getting Real About AI Governance

Open Until: 08/19/2024

Amidst the rampant hype about AI (especially Generative AI), there is a real story about how AI systems can be used to buil...

AI Organizational Responsibilities - Governance, Risk Management, and Cultural Aspects

Open Until: 08/20/2024

This paper is the second in a series focused on delineating organizational responsibilities for AI. Driven by the need to a...

AI in Medical Research: Applications & Considerations

Open Until: 08/20/2024

This research paper was created to explore the transformative impact of AI on healthcare. It aims to educate medical resear...