Security
Control Ownership Map
Which party owns each of the 207 CSA CCM v4.1 controls in our self-assessment -- Qualflare, shared, or the customer.
This page lists every one of the 207 controls in our CSA Cloud Controls Matrix v4.1 self-assessment by control ID, with who owns it -- Qualflare-owned (infrastructure/platform security you have no lever over), Shared (we build and operate the mechanism, you're responsible for using it), or Customer-owned (entirely your own configuration and practice). This is the control-ID-level detail the Shared Security Responsibility Model page summarizes by domain.
This page states ownership only -- not the status of our assessment against each control (met, partial, or a gap), which is part of the full CAIQ self-assessment available under NDA for formal vendor due diligence.
| Control | Title | Ownership |
|---|
| A&A-01 | Audit and Assurance Policy and Procedures | Shared |
| A&A-02 | Independent Assessments | Shared |
| A&A-03 | Risk Based Planning Assessment | Shared |
| A&A-04 | Requirements Compliance | Shared |
| A&A-05 | Audit Management Process | Shared |
| A&A-06 | Remediation | Shared |
| Control | Title | Ownership |
|---|
| AIS-01 | Application and Interface Security Policy and Procedures | Shared |
| AIS-02 | Application Security Baseline Requirements | Shared |
| AIS-03 | Application Security Metrics | Shared |
| AIS-04 | Secure Application Development Lifecycle | Qualflare-owned |
| AIS-05 | Application Security Testing | Shared |
| AIS-06 | Secure Application Deployment | Qualflare-owned |
| AIS-07 | Application Vulnerability Remediation | Shared |
| AIS-08 | API Security | Shared |
| Control | Title | Ownership |
|---|
| BCR-01 | Business Continuity Management Policy and Procedures | Shared |
| BCR-02 | Risk Assessment and Impact Analysis | Shared |
| BCR-03 | Business Continuity Strategy | Shared |
| BCR-04 | Business Continuity Planning | Shared |
| BCR-05 | Documentation | Shared |
| BCR-06 | Business Continuity Exercises | Shared |
| BCR-07 | Communication | Shared |
| BCR-08 | Backup | Shared |
| BCR-09 | Disaster Response Plan | Shared |
| BCR-10 | Response Plan Exercise | Shared |
| BCR-11 | Equipment Redundancy | Qualflare-owned |
| Control | Title | Ownership |
|---|
| CCC-01 | Change Management Policy and Procedures | Shared |
| CCC-02 | Quality Testing | Shared |
| CCC-03 | Change Management Technology | Shared |
| CCC-04 | Unauthorized Change Protection | Shared |
| CCC-05 | Change Agreements | Shared |
| CCC-06 | Change Management Baseline | Shared |
| CCC-07 | Detection of Baseline Deviation | Shared |
| CCC-08 | Exception Management | Shared |
| CCC-09 | Change Restoration | Shared |
| Control | Title | Ownership |
|---|
| CEK-01 | Encryption and Key Management Policy and Procedures | Shared |
| CEK-02 | CEK Roles and Responsibilities | Shared |
| CEK-03 | Data Protection | Shared |
| CEK-04 | Encryption Algorithm | Shared |
| CEK-05 | Encryption Change Management | Qualflare-owned |
| CEK-06 | Encryption Change Cost Benefit Analysis | Shared |
| CEK-07 | Encryption Risk Management | Shared |
| CEK-08 | Service Customer Key Management Capability | Shared |
| CEK-09 | Encryption and Key Management Audit | Shared |
| CEK-10 | Key Generation | Shared |
| CEK-11 | Key Purpose | Shared |
| CEK-12 | Key Rotation | Shared |
| CEK-13 | Key Revocation | Shared |
| CEK-14 | Key Destruction | Shared |
| CEK-15 | Key Activation | Shared |
| CEK-16 | Key Suspension | Shared |
| CEK-17 | Key Deactivation | Shared |
| CEK-18 | Key Archival | Shared |
| CEK-19 | Key Compromise | Shared |
| CEK-20 | Key Recovery | Shared |
| CEK-21 | Key Inventory Management | Shared |
| Control | Title | Ownership |
|---|
| DCS-01 | Physical and Environmental Security Policy and Procedures | Qualflare-owned |
| DCS-02 | Off-Site Equipment Disposal Policy and Procedures | Qualflare-owned |
| DCS-03 | Off-Site Transfer Authorization Policy and Procedures | Qualflare-owned |
| DCS-04 | Secure Area Policy and Procedures | Qualflare-owned |
| DCS-05 | Secure Media Transportation Policy and Procedures | Qualflare-owned |
| DCS-06 | Assets Classification | Shared |
| DCS-07 | Assets Cataloguing and Tracking | Shared |
| DCS-08 | Controlled Physical Access Points | Qualflare-owned |
| DCS-09 | Equipment Identification | Qualflare-owned |
| DCS-10 | Secure Area Authorization | Qualflare-owned |
| DCS-11 | Surveillance System | Qualflare-owned |
| DCS-12 | Adverse Event Response Training | Qualflare-owned |
| DCS-13 | Cabling Security | Qualflare-owned |
| DCS-14 | Environmental Systems | Qualflare-owned |
| DCS-15 | Secure Utilities | Qualflare-owned |
| DCS-16 | Equipment Location | Qualflare-owned |
| DCS-17 | Datacenter Metrics | Qualflare-owned |
| DCS-18 | Datacenter Operations Resilience | Qualflare-owned |
| Control | Title | Ownership |
|---|
| DSP-01 | Security and Privacy Policy and Procedures | Shared |
| DSP-02 | Secure Disposal | Shared |
| DSP-03 | Data Inventory | Shared |
| DSP-04 | Data Classification | Shared |
| DSP-05 | Data Flow Documentation | Shared |
| DSP-06 | Data Ownership and Stewardship | Shared |
| DSP-07 | Data Protection by Design and Default | Shared |
| DSP-08 | Data Privacy by Design and Default | Shared |
| DSP-09 | Data Protection Impact Assessment | Shared |
| DSP-10 | Sensitive Data Transfer | Shared |
| DSP-11 | Personal Data Access, Reversal, Rectification and Deletion | Shared |
| DSP-12 | Limitation of Purpose in Personal Data Processing | Shared |
| DSP-13 | Personal Data Sub-processing | Shared |
| DSP-14 | Disclosure of Data Sub-processors | Shared |
| DSP-15 | Limitation of Production Data Use | Shared |
| DSP-16 | Data Retention and Deletion | Shared |
| DSP-17 | Sensitive Data Protection | Qualflare-owned |
| DSP-18 | Disclosure Notification | Qualflare-owned |
| DSP-19 | Data Location | Shared |
| Control | Title | Ownership |
|---|
| GRC-01 | Governance Program Policy and Procedures | Shared |
| GRC-02 | Risk Management Program | Shared |
| GRC-03 | Organizational Policy Reviews | Shared |
| GRC-04 | Policy Exception Process | Shared |
| GRC-05 | Information Security Program | Shared |
| GRC-06 | Governance Responsibility Model | Shared |
| GRC-07 | Information System Regulatory Mapping | Shared |
| GRC-08 | Special Interest Groups | Shared |
| Control | Title | Ownership |
|---|
| HRS-01 | Background Screening Policy and Procedures | Shared |
| HRS-02 | Acceptable Use of Technology Policy and Procedures | Shared |
| HRS-03 | Clean Desk Policy and Procedures | Shared |
| HRS-04 | Remote and Home Working Policy and Procedures | Shared |
| HRS-05 | Asset returns | Shared |
| HRS-06 | Employment Termination | Shared |
| HRS-07 | Employment Agreement Process | Shared |
| HRS-08 | Employment Agreement Content | Shared |
| HRS-09 | Personnel Roles and Responsibilities | Shared |
| HRS-10 | Non-Disclosure Agreements | Shared |
| HRS-11 | Security Awareness Training | Shared |
| HRS-12 | Personal and Sensitive Data Awareness and Training | Shared |
| HRS-13 | Compliance User Responsibility | Shared |
| Control | Title | Ownership |
|---|
| IAM-01 | Identity and Access Management Policy and Procedures | Shared |
| IAM-02 | Credentials Management Policy and Procedures | Shared |
| IAM-03 | Identity Inventory | Shared |
| IAM-04 | Separation of Duties | Shared |
| IAM-05 | Least Privilege | Shared |
| IAM-06 | Access Provisioning | Shared |
| IAM-07 | Access Changes and Revocation | Shared |
| IAM-08 | Access Review | Shared |
| IAM-09 | Segregation of Privileged Access Roles | Shared |
| IAM-10 | Management of Privileged Access Roles | Shared |
| IAM-11 | Service Customers Approval for Agreed Privileged Access Roles | Shared |
| IAM-12 | Unique Identities | Shared |
| IAM-13 | Strong Authentication | Shared |
| IAM-14 | Credentials Management | Shared |
| IAM-15 | Authorization Mechanisms | Shared |
| Control | Title | Ownership |
|---|
| IPY-01 | Interoperability and Portability Policy and Procedures | Shared |
| IPY-02 | Application Interface Availability | Shared |
| IPY-03 | Secure Interoperability and Portability Management | Shared |
| IPY-04 | Data Portability Contractual Obligations | Shared |
| Control | Title | Ownership |
|---|
| I&S-01 | Infrastructure and Virtualization Security Policy and Procedures | Qualflare-owned |
| I&S-02 | Capacity and Resource Planning | Qualflare-owned |
| I&S-03 | Network Security | Qualflare-owned |
| I&S-04 | OS Hardening and Base Controls | Qualflare-owned |
| I&S-05 | Production and Non-Production Environments | Shared |
| I&S-06 | Segmentation and Segregation | Qualflare-owned |
| I&S-07 | Migration to Cloud Environments | Shared |
| I&S-08 | Network Architecture Documentation | Qualflare-owned |
| I&S-09 | Network Defense | Qualflare-owned |
| Control | Title | Ownership |
|---|
| LOG-01 | Logging and Monitoring Policy and Procedures | Shared |
| LOG-02 | Audit Logs Protection | Shared |
| LOG-03 | Security Monitoring and Alerting | Shared |
| LOG-04 | Audit Logs Access and Accountability | Shared |
| LOG-05 | Audit Logs Monitoring and Response | Shared |
| LOG-06 | Clock Synchronization | Qualflare-owned |
| LOG-07 | Logging Scope | Shared |
| LOG-08 | Audit Logs Sanitization | Shared |
| LOG-09 | Log Records | Shared |
| LOG-10 | Audit Records Protection | Shared |
| LOG-11 | Encryption Monitoring and Reporting | Shared |
| LOG-12 | Transaction/Activity Logging | Shared |
| LOG-13 | Access Control Logs | Qualflare-owned |
| LOG-14 | Failures and Anomalies Reporting | Shared |
| Control | Title | Ownership |
|---|
| SEF-01 | Security Incident Management Policy and Procedures | Shared |
| SEF-02 | Service Management Policy and Procedures | Shared |
| SEF-03 | Incident Response Plans | Shared |
| SEF-04 | Incident Response Testing | Shared |
| SEF-05 | Incident Response Metrics | Shared |
| SEF-06 | Event Triage Processes | Shared |
| SEF-07 | Incident Management and Response | Shared |
| SEF-08 | Security Breach Notification | Shared |
| SEF-09 | Incident Records Management | Shared |
| SEF-10 | Points of Contact Maintenance | Shared |
| Control | Title | Ownership |
|---|
| STA-01 | Supply Chain Risk Management Policies and Procedures | Shared |
| STA-02 | SSRM Policy and Procedures | Shared |
| STA-03 | SSRM Supply Chain | Shared |
| STA-04 | SSRM Guidance | Qualflare-owned |
| STA-05 | SSRM Control Ownership | Qualflare-owned |
| STA-06 | SSRM Documentation Review | Shared |
| STA-07 | SSRM Control Implementation | Shared |
| STA-08 | Supply Chain Inventory | Shared |
| STA-09 | Service Bill of Material (BOM) | Shared |
| STA-10 | Supply Chain Risk Management | Shared |
| STA-11 | Primary Service and Contractual Agreement | Shared |
| STA-12 | Supply Chain Agreement Review | Shared |
| STA-13 | Supply Chain Compliance Assessment | Shared |
| STA-14 | Supply Chain Service Agreement Compliance | Shared |
| STA-15 | Supply Chain Governance Review | Shared |
| STA-16 | Supply Chain Data Security Assessment | Shared |
| Control | Title | Ownership |
|---|
| TVM-01 | Threat and Vulnerability Management Policy and Procedures | Shared |
| TVM-02 | Malware and Malicious Instructions Protection Policy and Procedures | Shared |
| TVM-03 | Vulnerability Identification | Shared |
| TVM-04 | Threat Analysis and Modelling | Shared |
| TVM-05 | Detection Updates | Shared |
| TVM-06 | External Library Vulnerabilities | Qualflare-owned |
| TVM-07 | Penetration Testing | Qualflare-owned |
| TVM-08 | Vulnerability Remediation Schedule | Shared |
| TVM-09 | Vulnerability Prioritization | Shared |
| TVM-10 | Threat Response | Shared |
| TVM-11 | Vulnerability Management Reporting | Shared |
| TVM-12 | Vulnerability Management Metrics | Shared |
| Control | Title | Ownership |
|---|
| UEM-01 | Endpoint Devices Policy and Procedures | Shared |
| UEM-02 | Application and Service Approval | Shared |
| UEM-03 | Compatibility | Shared |
| UEM-04 | Endpoint Inventory | Shared |
| UEM-05 | Endpoint Management | Shared |
| UEM-06 | Automatic Lock Screen | Shared |
| UEM-07 | Operating Systems | Shared |
| UEM-08 | Storage Encryption | Shared |
| UEM-09 | Anti-Malware Detection and Prevention | Shared |
| UEM-10 | Software Firewall | Shared |
| UEM-11 | Data Loss Prevention | Shared |
| UEM-12 | Remote Locate | Shared |
| UEM-13 | Remote Wipe | Shared |
| UEM-14 | Third-Party Endpoint Security Posture | Shared |
Last updated: 2026-08-22