2026
Cloud Controls Matrix and CAIQ v4.1
Cloud Security Alliance, 4.1
CCM v4.1 contains 207 controls across 17 domains.
- Enterprise Assurance
- Security & Supply Chain
Evidence note
UK government guidance describing areas organisations may examine when assessing suppliers and their technical/security posture.
Why it matters. Lornets interpretation.
Enterprise scrutiny is fundamentally about whether technical claims relevant to the customer can be substantiated by evidence that is current and in scope.
This is the Lornets reading of the source, not a finding of the source itself.
Framework domains
Where this applies
2026
Cloud Security Alliance, 4.1
CCM v4.1 contains 207 controls across 17 domains.
2022
ISO / IEC, 2022 edition, with Amendment 1:2024 applicable
ISO/IEC 27001 addresses organisational information-security management.
2026
UK National Cyber Security Centre
The guidance uses assurance claims rather than treating high-level principles as self-evident.