ChaptersEventsBlog
Prove your skills in Illumiverse Labs’ Breach Containment CTF. Register now to stop attackers.
Research Publications currently filtered by Locale.
×

CSA Research Publications

Whitepapers, Reports and Other Resources

Home
Publications

Browse Publications

Recommendations for Adopting a Cloud-Native Key Management Service

Recommendations for Adopting a Cloud-Native Key Management Service

Release Date: 09/14/2021

Cloud-native key management services (KMS) offer organizations of any size and complexity a low-cost option for meeting their needs for key management, pa...

Request to download
The Evolution of STAR: Introducing Continuous Auditing

The Evolution of STAR: Introducing Continuous Auditing

Release Date: 09/14/2021

The CSA Continuous Auditing Certification (aka STAR Level 3) is the most rigorous assurance tier in the STAR program. Level 3 certified services providers...

Request to download
Microservices Architecture Pattern

Microservices Architecture Pattern

Release Date: 08/31/2021

This document provides a repeatable approach to architecting, developing, and deploying microservices as Microservices Architecture Patterns (MAPs). The p...

Request to download
Process for CSA International Standardization Council (ISC) Standards Liaison Officer

Process for CSA International Standardization Council (ISC) Standards Liaison Officer

Release Date: 08/18/2021

The Cloud Security Alliance (CSA) has designated a council to coordinate all aspects of standardization efforts within the CSA. The role of the council is...

Request to download
Protecting the Privacy of Healthcare Data in the Cloud

Protecting the Privacy of Healthcare Data in the Cloud

Release Date: 08/10/2021

The Health Delivery Organization (HDO) needs to understand the relationship between privacy and security, particularly the differences. This understanding...

Request to download
Cloud Threat Modeling

Cloud Threat Modeling

Release Date: 07/29/2021

The purpose of this document is to enable, encourage cloud and security practitioners to apply threat modeling for cloud applications, services, and security...

Request to download
Cloud Key Management Working Group Charter 2021

Cloud Key Management Working Group Charter 2021

Release Date: 07/20/2021

Cloud services are becoming ubiquitous in all sizes, and customers encounter many obligations and opportunities for using key management systems with thos...

Request to download
The Use of Blockchain in Healthcare

The Use of Blockchain in Healthcare

Release Date: 07/15/2021

Healthcare is a large and heavily regulated industry. US and EU privacy and security laws require healthcare organizations to protect personal information...

Request to download
Healthcare Cybersecurity Playbook - An Evolving Landscape

Healthcare Cybersecurity Playbook - An Evolving Landscape

Release Date: 07/14/2021

One aspect of healthcare that has increased significantly during the COVID-19 pandemic is the use of telehealth. Telehealth is used for everything from re...

Request to download
SecaaS Working Group Charter 2021

SecaaS Working Group Charter 2021

Release Date: 07/09/2021

This charter lays out the scope, responsibilities, and roadmap for the Security as a Service (SecaaS) Working Group. The SecaaS Working Group has been cre...

Request to download
Hyperledger Fabric 2.0 Architecture Security Report

Hyperledger Fabric 2.0 Architecture Security Report

Release Date: 06/28/2021

Blockchain technology is being rapidly adopted by enterprises to bring traceability and transparency to external business workflows. Considering that many...

Request to download
Hyperledger Fabric 2.0 Architecture Security Controls Checklist

Hyperledger Fabric 2.0 Architecture Security Controls Checklist

Release Date: 06/28/2021

Blockchain technology is being rapidly adopted by enterprises to bring traceability and transparency to external business workflows. Considering that many...

Request to download
Code of Practice for Implementing STAR Level 2

Code of Practice for Implementing STAR Level 2

Release Date: 06/23/2021

This Code of Practice shows how you can apply the CCM control set in your organization to reach STAR Level 2 third party certification/attestation and als...

Request to download
Critical Controls Implementation for Salesforce

Critical Controls Implementation for Salesforce

Release Date: 06/15/2021

The Salesforce Platform can be a valuable tool for organizations to build and test applications. However, certain security changes are needed when an orga...

Request to download
Telehealth Risk Management

Telehealth Risk Management

Release Date: 06/10/2021

The recent COVID-19 pandemic has increased the demand for data and accelerated the use of telehealth. The Health Resources and Services Administration (HRSA)...

Request to download
STAR Level 1: Security Questionnaire (CAIQ v4)

STAR Level 1: Security Questionnaire (CAIQ v4)

Release Date: 06/07/2021

The STAR Level 1: Security Questionnaire (CAIQ v4) offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,...

Request to download
Cloud Solution Data Science COVID-19 Dashboard

Cloud Solution Data Science COVID-19 Dashboard

Release Date: 05/27/2021

This publication was produced through the efforts of chapters and volunteers but the content development falls outside of the CSA Research Lifecycle. For ...

Request to download
CSA Enterprise Architecture Reference Guide

CSA Enterprise Architecture Reference Guide

Release Date: 05/18/2021

The Enterprise Architecture Reference Guide v2 is a companion piece with the EA v2 to CCM v3.0.1 Mapping. The peer review for both documents are intended to ...

Request to download
Enterprise Architecture Reference Diagram

Enterprise Architecture Reference Diagram

Release Date: 05/18/2021

The CSA Enterprise Architecture (EA) is both a methodology and a set of tools. It is a framework, a comprehensive approach for the architecture of a secure c...

Request to download
Enterprise Architecture v2 to CCM v3.01 Mapping Guide

Enterprise Architecture v2 to CCM v3.01 Mapping Guide

Release Date: 05/18/2021

The Enterprise Architecture (EA) is the CSA’s standard cloud reference architecture while the Cloud Control Matrix (CCM) is the CSA’s standard control set. T...

Request to download