Skip to main content

Tool

Common Cloud Controls

An open FINOS standard for technology-agnostic cloud security, resiliency and compliance controls with machine-verifiable assessments.

ccc.finos.org

Where it helps

  • Build a Governance Twin

    Provides shared threats, controls and assessment requirements that a Governance Twin can bind to cloud services and sensitive activities.

  • Governance Is Composable

    Supplies reusable baseline control content that teams can specialise for particular cloud services and environments.

  • Continuous Governance

    Assessment requirements can be exercised as behavioural checks in pipelines and representative environments, not only during periodic reviews.

  • Evidence by Default

    Assessment results and control evidence can be produced as durable machine-readable artefacts rather than spreadsheet attestations.