This presentation explores the Change Control and Configuration Management (CCCM) domain of the Cloud Control Matrix (CCM). With its nine control specifications, this domain focuses on mitigating risks associated with configuration changes to information technology (IT) assets by adherence to a robust change management process—regardless of whether IT assets are managed internally or externally. Proper handling of modifications is essential to ensure that changes do not introduce vulnerabilities or compromise the security and stability of cloud systems, which is critical for both Cloud Service Providers (CSPs) and Cloud Service Customers (CSCs).
Both CSPs and CSCs utilize the CCM controls to ensure that a secure cloud environment is configured and maintained in accordance with agreed service requirements. This domain ensures that IT asset configurations are only modified by an approved baseline and that any changes are authorized by the appropriate change management authority, whether CSP or CSC.