Question 36
UnclassifiedWhich of the following is a direct benefit of mapping the Cloud Control Matrix (CCM) to other international standards and regulations?
Correct answer: B
Explanation
Mapping the Cloud Control Matrix to other standards and regulations lets organizations reuse one control framework across multiple requirements. That directly “streamline[s] their own compliance and security efforts” by reducing duplicate work for cloud service providers and customers.
Why each option is right or wrong
A. CCM mapping entitles cloud service providers to be listed as an approved supplier for tenders and government contracts.
B. CCM mapping enables cloud service providers and customers alike to streamline their own compliance and security efforts.
The Cloud Control Matrix (CCM) is designed as a control framework that can be cross-referenced against other standards and regulations, so one set of controls can satisfy multiple compliance obligations at once. In practice, that reduces duplicated control design, testing, and documentation for both cloud service providers and customers, which is why the benefit is streamlined compliance and security management rather than a new standalone legal requirement.
C. CCM mapping enables an uninterrupted data flow and, in particular, the export of personal data across different jurisdictions.
D. CCM mapping entitles cloud service providers to be certified under the CSA STAR program.