{"id":8588,"date":"2024-02-28T19:40:11","date_gmt":"2024-02-28T19:40:11","guid":{"rendered":"https:\/\/www.satup.xyz\/index.php\/2024\/02\/28\/the-adobe-common-controls-framework-ccf-version-5-0-is-now-available-adds-controls-from-pci-dss-v4-0-bsi-c5-and-more-by-renae-kang-feb-2024\/"},"modified":"2024-02-28T19:40:11","modified_gmt":"2024-02-28T19:40:11","slug":"the-adobe-common-controls-framework-ccf-version-5-0-is-now-available-adds-controls-from-pci-dss-v4-0-bsi-c5-and-more-by-renae-kang-feb-2024","status":"publish","type":"post","link":"https:\/\/www.satup.xyz\/index.php\/2024\/02\/28\/the-adobe-common-controls-framework-ccf-version-5-0-is-now-available-adds-controls-from-pci-dss-v4-0-bsi-c5-and-more-by-renae-kang-feb-2024\/","title":{"rendered":"The Adobe Common Controls Framework (CCF) Version 5.0 is Now Available | Adds Controls from PCI DSS v4.0, BSI C5, and More | by Renae Kang | Feb, 2024"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<div>\n<h2 id=\"9186\" class=\"pw-subtitle-paragraph hq gs gt be b hr hs ht hu hv hw hx hy hz ia ib ic id ie if cp dt\">By <a class=\"af ig\" href=\"https:\/\/www.linkedin.com\/in\/rahatsethi\/\" rel=\"noopener ugc nofollow\" target=\"_blank\">Rahat Sethi<\/a>, Director of Technology Governance, Risk &amp; Compliance<\/h2>\n<div class=\"ih ii ij ik il\">\n<div class=\"speechify-ignore ab co\">\n<div class=\"speechify-ignore bg l\">\n<div class=\"im in io ip iq ab\">\n<div>\n<div class=\"ab ir\"><a href=\"https:\/\/medium.com\/@renaekang97?source=post_page-----4b6491e91370--------------------------------\" rel=\"noopener follow\"><\/p>\n<div>\n<div class=\"bl\" aria-hidden=\"false\">\n<div class=\"l is it bx iu iv\">\n<div class=\"l fi\"><img loading=\"lazy\" decoding=\"async\" alt=\"Renae Kang\" class=\"l fc bx dc dd cw\" src=\"https:\/\/miro.medium.com\/v2\/resize:fill:88:88\/1*_2c2rNBYDHH7262294wRcA.jpeg\" width=\"44\" height=\"44\" loading=\"lazy\" data-testid=\"authorPhoto\"\/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/a><a href=\"https:\/\/blog.developer.adobe.com\/?source=post_page-----4b6491e91370--------------------------------\" rel=\"noopener  ugc nofollow\"><\/p>\n<div class=\"iy ab fi\">\n<div>\n<div class=\"bl\" aria-hidden=\"false\">\n<div class=\"l iz ja bx iu jb\">\n<div class=\"l fi\"><img loading=\"lazy\" decoding=\"async\" alt=\"Adobe Tech Blog\" class=\"l fc bx bq jc cw\" src=\"https:\/\/miro.medium.com\/v2\/resize:fill:48:48\/1*riyFijvwTfGcWNf1guRNtg.png\" width=\"24\" height=\"24\" loading=\"lazy\" data-testid=\"publicationPhoto\"\/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<figure class=\"np nq nr ns nt nu nm nn paragraph-image\">\n<div role=\"button\" tabindex=\"0\" class=\"nv nw fi nx bg ny\">\n<div class=\"nm nn no\"><picture><source srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/format:webp\/1*G7-p3E_kud6s8zWKHl45kg.png 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/format:webp\/1*G7-p3E_kud6s8zWKHl45kg.png 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/format:webp\/1*G7-p3E_kud6s8zWKHl45kg.png 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/format:webp\/1*G7-p3E_kud6s8zWKHl45kg.png 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/format:webp\/1*G7-p3E_kud6s8zWKHl45kg.png 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/format:webp\/1*G7-p3E_kud6s8zWKHl45kg.png 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1400\/format:webp\/1*G7-p3E_kud6s8zWKHl45kg.png 1400w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px\" type=\"image\/webp\"\/><source data-testid=\"og\" srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/1*G7-p3E_kud6s8zWKHl45kg.png 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/1*G7-p3E_kud6s8zWKHl45kg.png 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/1*G7-p3E_kud6s8zWKHl45kg.png 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/1*G7-p3E_kud6s8zWKHl45kg.png 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/1*G7-p3E_kud6s8zWKHl45kg.png 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/1*G7-p3E_kud6s8zWKHl45kg.png 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1400\/1*G7-p3E_kud6s8zWKHl45kg.png 1400w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 700px\"\/><img fetchpriority=\"high\" alt=\"\" class=\"bg mt nz c\" width=\"700\" height=\"412\" loading=\"eager\" role=\"presentation\"\/><\/picture><\/div>\n<\/div>\n<\/figure>\n<p id=\"8a56\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\">To address the evolving landscape of regulatory and security framework requirements, Adobe is excited to announce the latest version of our open-source Common Controls Framework (CCF). This new version was crafted with a focus on customer needs and assessor expectations by considering some of the industry-trending and security-focused best practices and frameworks.<\/p>\n<p id=\"7aad\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\"><strong class=\"oc gu\">What\u2019s New in Adobe Common Control Framework Version 5.0?<\/strong><\/p>\n<p id=\"aaec\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\">Adobe CCF version 5.0 prioritizes the critical cloud and hybrid security controls required by organizations to meet the industry standards of public sector, healthcare, and financial services firms around the world. The new version of CCF has been updated with controls pertaining to the following frameworks:<\/p>\n<ul class=\"\">\n<li id=\"62c3\" class=\"oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov ow ox oy bj\"><a class=\"af ig\" href=\"https:\/\/docs-prv.pcisecuritystandards.org\/PCI%20DSS\/Standard\/PCI-DSS-v4_0.pdf\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">Payment Card Industry DSS v4.0<\/strong><\/a>: Security standard designed to protect payment card data<\/li>\n<li id=\"52a3\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><a class=\"af ig\" href=\"https:\/\/www.bsi.bund.de\/EN\/Themen\/Unternehmen-und-Organisationen\/Informationen-und-Empfehlungen\/Empfehlungen-nach-Angriffszielen\/Cloud-Computing\/Kriterienkatalog-C5\/kriterienkatalog-c5_node.html\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">Cloud Computing Compliance Criteria Catalogue (C5)<\/strong><\/a>: Security standard developed by the German Federal office of Information Security for cloud service providers<\/li>\n<li id=\"a0a7\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><a class=\"af ig\" href=\"https:\/\/www.iso.org\/standard\/43757.html\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">ISO\/IEC 27017<\/strong><\/a><strong class=\"oc gu\">: <\/strong>International standard offering guidelines for information security controls specific to cloud services<\/li>\n<li id=\"6a21\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><a class=\"af ig\" href=\"https:\/\/www.iso.org\/standard\/76559.html\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">ISO\/IEC 27018<\/strong><\/a><strong class=\"oc gu\">:<\/strong> International standard offering guidelines for protection of personally identifiable information (PII) in cloud services<\/li>\n<li id=\"f51b\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><a class=\"af ig\" href=\"https:\/\/www.fedramp.gov\/understanding-baselines-and-impact-levels\/\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">FedRAMP Moderate<\/strong><\/a><strong class=\"oc gu\">:<\/strong> U.S. Government cybersecurity standard for cloud services, which ensures a moderate level of security controls<\/li>\n<li id=\"d68b\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><strong class=\"oc gu\">Japan\u2019s <\/strong><a class=\"af ig\" href=\"https:\/\/www.ismap.go.jp\/csm?id=kb_article_view&amp;sysparm_article=KB0010301&amp;sys_kb_id=5370ef9bdbb1a1506e6cb915f396192c&amp;spa=1\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">Information System Security Management Systems and Assessment Program (ISMAP)<\/strong><\/a><strong class=\"oc gu\">:<\/strong> Japanese government security framework for assessing the security of cloud service providers to participate in public sector projects<\/li>\n<li id=\"5669\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><strong class=\"oc gu\">Korean FSI CSP Evaluation:<\/strong> Cloud service provider self-evaluation to meet Regulation on Supervision of Electronic Financial Transactions (RSEFT)<\/li>\n<li id=\"457b\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><a class=\"af ig\" href=\"https:\/\/www.cisecurity.org\/controls\/v8?sc_camp=BB43A1FDB3874AABA535F539EDD34A19&amp;gad_source=1\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">CIS Critical Security Controls Version 8 (CIS V8)<\/strong><\/a><strong class=\"oc gu\">:<\/strong> Prioritized set of safeguards that help mitigate the most prevalent cyber-attacks against systems and networks<\/li>\n<li id=\"94ee\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><a class=\"af ig\" href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/cyber-essentials\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">U.K.\u2019s Cyber Essentials<\/strong><\/a><strong class=\"oc gu\">:<\/strong> Guide for leaders of small businesses as well as leaders of local government agencies to develop an actionable understanding of where to start implementing organizational cybersecurity practices<\/li>\n<li id=\"1e6b\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><a class=\"af ig\" href=\"https:\/\/www.mas.gov.sg\/\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">Monetary Authority of Singapore (MAS)<\/strong><\/a><strong class=\"oc gu\">: <\/strong>Regulatory standards set by the Monetary Authority of Singapore to ensure the integrity and security of financial operations within the jurisdiction<\/li>\n<\/ul>\n<p id=\"7fbb\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\"><strong class=\"oc gu\">Additional Updates in CCF v5.0<\/strong><\/p>\n<p id=\"c09a\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\">We\u2019ve also added the following new control attributes to CCF version 5.0:<\/p>\n<ul class=\"\">\n<li id=\"33eb\" class=\"oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov ow ox oy bj\"><strong class=\"oc gu\">Control Implementation Guidance: <\/strong>Provides<strong class=\"oc gu\"> <\/strong>guidance for users to understand how to implement required controls. Customers can customize this guidance based on the tools and technologies used within the organization.<\/li>\n<li id=\"2134\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><strong class=\"oc gu\">Control Testing Procedures:<\/strong> Provides guidance for security and risk management professionals to understand how to test controls at both the design and implementation levels.<\/li>\n<li id=\"9198\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><strong class=\"oc gu\">Control Type:<\/strong> Categorizing controls by type, including <em class=\"pe\">Preventive<\/em>, <em class=\"pe\">Detective<\/em>, or <em class=\"pe\">Corrective<\/em>, provides organizations a clear perspective of the control\u2019s impact when the control evades a risk associated with the potential occurrence of an information security incident.<\/li>\n<li id=\"e6f9\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><strong class=\"oc gu\">Control Theme:<\/strong> Control themes categorized by <em class=\"pe\">People<\/em>, <em class=\"pe\">Process<\/em>, and <em class=\"pe\">Technology<\/em> help identify and align processes for better implementation and testing around the controls.<\/li>\n<li id=\"3050\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><strong class=\"oc gu\">Audit Artifacts: <\/strong>Examples of what auditors generally request while testing are provided to help substantiate their conclusions and findings during an audit.<\/li>\n<li id=\"446e\" class=\"oa ob gt oc b hr oz oe of hu pa oh oi oj pb ol om on pc op oq or pd ot ou ov ow ox oy bj\"><strong class=\"oc gu\">Policies and Standards Mapping: <\/strong>Recommended policies and standards help drive control requirements, enabling the governance of the control and providing guidance related to the control ownership within the organization.<\/li>\n<\/ul>\n<p id=\"3641\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\"><strong class=\"oc gu\">Download the Open Source CCF v5.0<\/strong><\/p>\n<p id=\"77d7\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\">Organizations of all sizes and sectors can tailor the CCF to their unique security compliance objectives. Integrating the CCF into your compliance workflow will help your company achieve a more scalable security compliance posture for ongoing success. We invite you to <a class=\"af ig\" href=\"https:\/\/survey.adobe.com\/jfe\/form\/SV_0k1xCQJw84DRpTU\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">download the newly released CCF v5.0<\/strong><\/a> for your organization today.<\/p>\n<p id=\"8f62\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\">For more information about the Adobe CCF, please visit the <a class=\"af ig\" href=\"https:\/\/www.adobe.com\/trust\/compliance\/adobe-ccf.html\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">Adobe Trust Center<\/strong><\/a>.<\/p>\n<p id=\"bad7\" class=\"pw-post-body-paragraph oa ob gt oc b hr od oe of hu og oh oi oj ok ol om on oo op oq or os ot ou ov gm bj\">To share feedback, questions, or collaborative inquiries about the framework, contact us at <a class=\"af ig\" href=\"https:\/\/blog.developer.adobe.com\/mailto:opensourceccf@adobe.com\" rel=\"noopener ugc nofollow\" target=\"_blank\"><strong class=\"oc gu\">opensourceccf@adobe.com<\/strong><\/a>.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/blog.developer.adobe.com\/the-adobe-common-controls-framework-ccf-version-5-0-4b6491e91370?source=rss----9342990108af---4\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Rahat Sethi, Director of Technology Governance, Risk &amp; Compliance To address the evolving landscape of regulatory and security framework requirements, Adobe is excited to announce the latest version of our open-source Common Controls Framework (CCF). This new version was crafted with a focus on customer needs and assessor expectations by considering some of the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":8589,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[19],"tags":[],"class_list":["post-8588","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-graphics-design"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts\/8588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/comments?post=8588"}],"version-history":[{"count":0,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/posts\/8588\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/media\/8589"}],"wp:attachment":[{"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/media?parent=8588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/categories?post=8588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.satup.xyz\/index.php\/wp-json\/wp\/v2\/tags?post=8588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}