This repository contains Terraform modules and configuration examples for creating secure, compliant cloud storage solutions that align with the FINOS Common Cloud Controls (CCC) standard.
- Secure by Default: Terraform modules that implement CCC security controls out of the box
- Multi-Cloud Support: Configurations for AWS S3, Azure Storage, and Google Cloud Storage
- Production Ready: Battle-tested configurations suitable for financial services environments
- Compliance Focused: Each configuration maps to specific CCC controls and requirements
Browse the /config directory for ready-to-use configuration example for aws, azure or gcp.
For the complete list of controls and their implementation details, see the CCC Standard.
You can review the results of testing the above configurations on the CCC Website
The testing system:
- Discovers resources automatically using cloud provider APIs
- Runs Gherkin tests filtered by catalog type (CCC.ObjStor, CCC.Core, etc.)
- Generates reports in HTML and OCSF JSON formats
See the Testing README for full documentation on architecture, adding new services, and writing tests.
- Check the issues to see if there's anything you'd like to work on
- Raise a GitHub Issue to ask questions or make suggestions
- Pull Requests are always welcome - the main branch is considered an iterative development branch
This project is part of the broader CCC initiative. Join the Compliant Financial Infrastructure working group:
- When: 10AM UK Thursday / 5PM UK on 4th Thursday each month
- See: calendar.finos.org
- Chair: @eddie-knight
- Mailing List: cfi+subscribe@lists.finos.org
Find meetings on the FINOS Community Calendar and browse Past Meeting Minutes.
All commits must be signed with a DCO signature to avoid being flagged by the DCO Bot. This means that your commit log message must contain a line that looks like the following one, with your actual name and email address:
Signed-off-by: John Doe <john.doe@example.com>
Adding the -s flag to your git commit will add that line automatically. You can also add it manually as part of your commit log message or add it afterwards with git commit --amend -s.
Copyright 2025 FINOS
Distributed under the Apache License, Version 2.0.
SPDX-License-Identifier: Apache-2.0
Please see our Security Policy for reporting vulnerabilities.
Participants should follow the FINOS Code of Conduct: https://community.finos.org/docs/governance/code-of-conduct