Cloud Control Matrix (CCM)

The Cloud Control Matrix (CCM) is a cybersecurity control framework developed by the Cloud Security Alliance (CSA) that provides a comprehensive set of security and compliance controls for cloud computing environments. From the Cloud Security Alliance: The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations with the needed structure, detail and clarity relating to information security tailored to cloud computing. CCM is currently considered a de-facto standard for cloud security assurance and compliance. ...

1 min

Cloud Security Alliance (CSA)

The Cloud Security Alliance (CSA) is a nonprofit organization that promotes best practices for securing cloud computing environments through research, education, and industry collaboration. Related Cloud Control Matrix (CCM)

1 min

COBIT

COBIT is an IT Controls and Governance framework developed and maintained by ISACA. The current version is COBIT 2019. Further reading COBIT - Wikipedia

1 min

Code Review

Code review is a quality control process in software development where a second reviewer examines code changes to identify potential defects and to improve overall code quality. Further reading Code Review Guide (OWASP) (PDF) Code review (Wikipedia) Security-Oriented Code Review (NIST)

1 min

Continuous Threat Exposure Management (CTEM)

Continuous Threat Exposure Management (CTEM) is a way of looking at cybersecurity risk through the lens of β€œwhat could really hurt us, and how do we stay ahead of it?” Instead of one-off assessments or annual tests, CTEM is a continuous cycle that helps technology leaders see where the organisation is exposed, judge which issues matter most, and act before attackers do. CTEM runs through five stages: Scoping β€” deciding which parts of the business or technology estate to focus on. Discovery β€” identifying the vulnerabilities, misconfigurations, or exposures in that scope Prioritisation β€” weighing which findings actually matter, based on business impact and likelihood Validation β€” testing whether the exposure is real and exploitable, avoiding wasted effort. Mobilisation β€” taking action, whether that’s fixing, monitoring, or planning mitigations. Together, these stages create a loop of constant visibility and improvement, helping executives translate technical risks into business decisions and resource allocation. ...

1 min