Skip to main content

Use Cases

Financial Institutions

Use Case: A bank or large financial institution operates multiple cloud platforms and has a dedicated team responsible for cloud security, architecture, compliance, and control assurance.

The organization already maintains internal policies and control requirements but needs a consistent way to assess cloud services, identify relevant threats, and map technical controls across cloud providers.

How FINOS CCC Can Be Used​

The cloud security team can use the FINOS CCC catalogs as a common reference when reviewing new cloud services and architectures.

A typical workflow could include:

  • Identify the cloud services and capabilities used by the proposed architecture.
  • Review the threats associated with those capabilities.
  • Select the relevant FINOS CCC controls.
  • Map the controls to the organization's internal policies, regulatory requirements, and risk framework.
  • Review the available test results to understand which controls can be technically validated.
  • Identify gaps where additional evidence, compensating controls, or risk acceptance may be required.
  • Integrate applicable tests into continuous compliance or policy-as-code pipelines.

Example: A development team proposes a new application using managed Kubernetes, cloud storage, and a managed database. The cloud security team uses the catalogs to:

  • Identify threats related to public exposure, identity, encryption, logging, and data protection;
  • Retrieve applicable controls for each cloud capability;
  • Map those controls to internal cloud security requirements;
  • Determine which controls can be automatically tested;
  • Request evidence for controls that cannot be validated automatically;
  • Document any remaining risks before the architecture is approved.

Outcomes: the organization gains:

  • A consistent cloud security review process;
  • Reusable mappings between FINOS CCC and internal controls;
  • Better traceability between threats, controls, tests, and evidence;
  • Reduced duplication across cloud platforms and security teams;
  • Opportunities to automate control validation.