2026
Practitioner Reference
Cloud Controls Matrix and CAIQ v4.1
CCM v4.1 contains 207 controls across 17 domains.
Cloud Security Alliance, 4.1
- Enterprise Assurance
- Security & Supply Chain
Evidence note
UK government guidance describing areas organisations may examine when assessing suppliers and their technical/security posture.
Why it matters. Lornets interpretation.
Enterprise scrutiny is fundamentally about whether technical claims relevant to the customer can be substantiated by evidence that is current and in scope.
This is the Lornets reading of the source, not a finding of the source itself.
Framework domains
Where this applies
Last verified 2026-08-11
2026
Practitioner Reference
CCM v4.1 contains 207 controls across 17 domains.
Cloud Security Alliance, 4.1
2022
Technical Standard
ISO/IEC 27001 addresses organisational information-security management.
ISO / IEC, 2022 edition, with Amendment 1:2024 applicable
2026
Government Guidance
The guidance uses assurance claims rather than treating high-level principles as self-evident.
UK National Cyber Security Centre