FINOS Common Cloud Controls
Open standard for consistent cloud security controls in financial services. Defines cybersecurity, resiliency, and compliance controls for common cloud services across major providers.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| CCC-C01 | Prevent Unencrypted Requests | |
| CCC-C02 | Ensure Data Encryption at Rest Utilizes Customer Managed Encryption Keys | |
| CCC-C03 | Implement Multi-Factor Authentication (MFA) for Access | |
| CCC-C04 | Log All Access and Changes | |
| CCC-C05 | Prevent Access from Untrusted Entities | |
| CCC-C06 | Ensure Resource Inventory | |
| CCC-C07 | Implement Change Management Procedures | |
| CCC-C08 | Enable Security Monitoring and Alerting | |
| CCC-C09 | Implement Network Segmentation | |
| CCC-C10 | Implement Vulnerability Management | |
| CCC-C11 | Implement Identity and Access Management (IAM) | |
| CCC-C12 | Enforce Least Privilege Access | |
| CCC-C13 | Implement Backup and Recovery | |
| CCC-C14 | Maintain Secure Configuration Baselines | |
| CCC-C15 | Implement Incident Response Procedures | |
| CCC-C16 | Ensure Data Classification and Handling | |
| CCC-C17 | Enable Audit Logging for Cloud Services |