Skip to main content

Core / Core

CCC Common Cloud Controls Core Controls

Version: v2025.10

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.Core.CN01Encrypt Data for TransmissionEnsure that all communications are encrypted in transit to protect data integrity and confidentiality.Encryption145
CCC.Core.CN02Encrypt Data for StorageEnsure that all data stored is encrypted at rest using strong encryption algorithms.Encryption141
CCC.Core.CN03Implement Multi-factor Authentication (MFA) for AccessEnsure that all sensitive activities require two or more identity factors during authentication to prevent unauthorized access.Access Control114
CCC.Core.CN04Log All Access and ChangesEnsure that all access attempts are logged to maintain a detailed audit trail for security and compliance purposes.Observability113
CCC.Core.CN05Prevent Access from Untrusted EntitiesEnsure that secure access controls enforce the principle of least privilege to restrict access to authorized entities from explicitly trusted sources only.Access Control156
CCC.Core.CN06Restrict Deployments to Trust PerimeterEnsure that the service and its child resources are only deployed on infrastructure in locations that are explicitly included within a defined trust perimeter.Data Resilience112
CCC.Core.CN07Alert on Unusual Enumeration ActivityEnsure that logs and associated alerts are generated when unusual enumeration activity is detected that may indicate reconnaissance activities.Observability122
CCC.Core.CN08Replicate Data to Multiple LocationsEnsure that data is replicated across multiple physical locations to protect against data loss due to hardware failures, natural disasters, or other catastrophic events.Data Resilience132
CCC.Core.CN09Ensure Integrity of Access LogsEnsure that access logs are always recorded to an external location that cannot be manipulated from the context of the service(s) it contains logs for.Observability333
CCC.Core.CN10Restrict Data Replication to Trust PerimeterEnsure that data is only replicated on infrastructure in locations that are explicitly included within a defined trust perimeter.Data Resilience121
CCC.Core.CN11Protect Encryption KeysEnsure that encryption keys are managed securely by enforcing the use of approved algorithms, regular key rotation, and customer-managed encryption keys (CMEKs).Encryption136
CCC.Core.CN13Minimize Lifetime of Encryption and Authentication CertificatesEnsure that encryption and authentication certificates have a limited lifetime to reduce the risk of compromise and ensure the use of up-to-date security practices.Encryption103
CCC.Core.CN14Maintain Recent BackupsEnsure that all backups used for disaster recovery are recent and subject to a retention policy that limits deletion.Data Resilience103