FINOS Common Cloud Controls
Open standard for consistent cloud security controls in financial services. Defines cybersecurity, resiliency, and compliance controls for common cloud services across major providers.
AC Access Control
| Control | Name | FINOS CCC References |
|---|---|---|
| AC-02 | Account Management | CCC-C11 |
| AC-03 | Access Enforcement | CCC-C05CCC-C11 |
| AC-04 | Information Flow Enforcement | CCC-C05CCC-C09 |
| AC-06 | Least Privilege | CCC-C11CCC-C12 |
| AC-16 | Automated Labeling | CCC-C16 |
| AC-17 | Remote Access | CCC-C05 |
| AC-20 | Use Of External Information Systems | CCC-C05 |
AU Audit and Accountability
CA Security Assessment and Authorization
CM Configuration Management
| Control | Name | FINOS CCC References |
|---|---|---|
| CM-02 | Baseline Configuration | CCC-C14 |
| CM-03 | Configuration Change Control | CCC-C07 |
| CM-04 | Monitoring Configuration Changes | CCC-C07 |
| CM-05 | Access Restrictions For Change | CCC-C07 |
| CM-06 | Configuration Settings | CCC-C14 |
| CM-07 | Least Functionality | CCC-C14 |
| CM-08 | Information System Component Inventory | CCC-C06 |
| CM-09 | Configuration Management Plan | CCC-C07 |
| CM-12 | Information Location | CCC-C06CCC-C16 |
| CM-13 | Data Action Mapping | CCC-C04CCC-C16 |
| CM-14 | Signed Components | CCC-C07 |
CP Contingency Planning
IA Identification and Authentication
IR Incident Response
MP Media Protection
PL Planning
PM Program Management
| Control | Name | FINOS CCC References |
|---|---|---|
| PM-05 | System Inventory | CCC-C06 |
RA Risk Assessment
SC System and Communications Protection
| Control | Name | FINOS CCC References |
|---|---|---|
| SC-07 | Boundary Protection | CCC-C05CCC-C09 |
| SC-08 | Transmission Integrity | CCC-C01 |
| SC-12 | Cryptographic Key Establishment And Management | CCC-C02 |
| SC-13 | Use Of Cryptography | CCC-C01 |
| SC-23 | Session Authenticity | CCC-C01 |
| SC-28 | Protection of Information at Rest | CCC-C02 |
| SC-32 | System Partitioning | CCC-C09 |
| SC-46 | Cross Domain Policy Enforcement | CCC-C09 |
| SC-48 | Sensor Relocation | CCC-C08 |