graphgrc

SCF - CLD-06.1 - Customer Responsibility Matrix (CRM)

Mechanisms exist to formally document a Customer Responsibility Matrix (CRM), delineating assigned responsibilities for controls between the Cloud Service Provider (CSP) and its customers.

Mapped framework controls

ISO 27001

ISO 27002

Control questions

Does the organization formally document a Customer Responsibility Matrix (CRM), delineating assigned responsibilities for controls between the Cloud Service Provider (CSP) and its customers?