The Continuous Audit Metrics Catalog

Logo
Presented by

Max Pritikin

About this talk

Cloud providers can take full advantage of continuous auditing once standards and best practices for automated assurance tooling exist. We have translated a subset of CCMv4 controls into quantitative characteristics of the cloud service in the form of ISO/IEC 19086 SLOs. The proposed practices for these metrics highlight interconnections between domains and demonstrates how even a small number of metrics can provide assurance for a large number of security objectives. This approach enables organizations to review and measure practices for effectiveness and supports automated certification and evaluation goals such as are found in CMMC Level4 and EU-SEC requirements.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (178)
Subscribers (16083)
Go in depth into CSA's latest research on everything from IoT to containers to blockchain. Webcasts will break down the research, provide use cases, instructions for implementation, and further insights.