Skip to main content
Lornets

Evidence note

Cloud Controls Matrix and CAIQ v4.1

Practitioner Reference2026Cloud Security Alliance

What does it cover?

A structured cloud-security assurance framework and associated consensus assessment questionnaire.

Key points

  1. 01CCM v4.1 contains 207 controls across 17 domains.
  2. 02CAIQ v4.1 contains 283 assurance questions aligned to the framework.
  3. 03The framework illustrates how structured customer assurance can extend across many security and operational areas.

Why it matters. Lornets interpretation.

Enterprise readiness is better understood as a claims-and-evidence problem than a questionnaire-writing exercise. The customer needs defensible technical evidence behind relevant answers.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 01Not every enterprise procurement process uses CSA.
  2. 02Completing CAIQ does not independently establish that a supplier is secure.
  3. 03Self-assessment and independent assurance are distinct forms of evidence.

Source

Organisation
Cloud Security Alliance
Evidence type
Practitioner Reference
Published
2026-01-27
Version
4.1
Status
Current

View the original source

Relevant Lornets framework areas

Framework domains

  • Security & Access Control
  • Data & Privacy Engineering
  • Reliability & Recoverability
  • Observability & Operations

Where this applies

Related evidence

Government Guidance

2026

Supplier Assurance Questions

UK National Cyber Security Centre

Supplier assurance can include governance, incident recovery, cloud configuration, privileged access, bespoke software security, data handling, testing and certification.

  • Enterprise Assurance
  • Security & Supply Chain
  • Reliability & Operations

Read Evidence Note

Technical Standard

2022

ISO/IEC 27001:2022

ISO / IEC, 2022 edition, with Amendment 1:2024 applicable

ISO/IEC 27001 addresses organisational information-security management.

  • Enterprise Assurance
  • Security & Supply Chain

Read Evidence Note

Source record

Published
2026-01-27
Last verified
2026-08-11
Source status
Current