Use Case: A bank or large financial institution operates multiple cloud platforms and has a dedicated team responsible for cloud security, architecture, compliance, and control assurance.
The organization already maintains internal policies and control requirements but needs a consistent way to assess cloud services, identify relevant threats, and map technical controls across cloud providers.
How FINOS CCC Can Be Used
The cloud security team can use the FINOS CCC catalogs as a common reference when reviewing new cloud services and architectures.
A typical workflow could include:
- Identify the cloud services and capabilities used by the proposed architecture.
- Review the threats associated with those capabilities.
- Select the relevant FINOS CCC controls.
- Map the controls to the organization's internal policies, regulatory requirements, and risk framework.
- Review the available test results to understand which controls can be technically validated.
- Identify gaps where additional evidence, compensating controls, or risk acceptance may be required.
- Integrate applicable tests into continuous compliance or policy-as-code pipelines.
Example: A development team proposes a new application using managed Kubernetes, cloud storage, and a managed database. The cloud security team uses the catalogs to:
- Identify threats related to public exposure, identity, encryption, logging, and data protection;
- Retrieve applicable controls for each cloud capability;
- Map those controls to internal cloud security requirements;
- Determine which controls can be automatically tested;
- Request evidence for controls that cannot be validated automatically;
- Document any remaining risks before the architecture is approved.
Outcomes: the organization gains:
- A consistent cloud security review process;
- Reusable mappings between FINOS CCC and internal controls;
- Better traceability between threats, controls, tests, and evidence;
- Reduced duplication across cloud platforms and security teams;
- Opportunities to automate control validation.