Tool
Common Cloud Controls
An open FINOS standard for technology-agnostic cloud security, resiliency and compliance controls with machine-verifiable assessments.
Where it helps
- Build a Governance Twin
Provides shared threats, controls and assessment requirements that a Governance Twin can bind to cloud services and sensitive activities.
- Governance Is Composable
Supplies reusable baseline control content that teams can specialise for particular cloud services and environments.
- Continuous Governance
Assessment requirements can be exercised as behavioural checks in pipelines and representative environments, not only during periodic reviews.
- Evidence by Default
Assessment results and control evidence can be produced as durable machine-readable artefacts rather than spreadsheet attestations.