CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | SaaS Governance Best Practices for Cloud Customers Release Date: 10/10/2022 In the context of cloud security, the focus is almost always on securing Infrastructure-as-a-Service (IaaS) environments. This is despite the reality that... Request to download |
![]() | Release Date: 10/04/2022 This document is an addendum to the CCM V4.0 that contain controls mapping between the CSA CCM and Japan's Information System Security Management and Asse... Request to download |
![]() | Release Date: 09/26/2022 When Health Information Technology systems seamlessly exchange data with each other, it is referred to as interoperability. Interoperability occurs when i... Request to download |
![]() | Recommendations for using a Customer Controlled Key Store Release Date: 09/26/2022 In the latest from the Cloud Key Management working group, this document provides guidance on how to assess and implement cloud key management services co... Request to download |
![]() | Accedere: Using a SOC 2 Approach to Help Organizations Achieve CSA STAR Level 2 Release Date: 09/19/2022 Cybersecurity frameworks, standards and certifications can be quite complicated to understand, making it difficult to identify which standard an organizat... Request to download |
![]() | The State of Cloud Security Risk, Compliance, and Misconfigurations - Korean Translation Release Date: 09/07/2022 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | Security Guidelines for Providing and Consuming APIs - Korean Translation Release Date: 08/17/2022 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | Cloud and Web Security Challenges in 2022 Release Date: 08/16/2022 Organizations’ work environments have undergone rapid but lasting changes in the face of the recent health crisis. Remote work became a necessity and many... Request to download |
![]() | Secure Connection Requirements of Hybrid Cloud - Korean Translation Release Date: 08/15/2022 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | Top Threats Working Group Charter 2022 Release Date: 08/11/2022 The Top Threats Working Group aims to provide up-to-date, industry-informed expert insights on cloud security risks, threats, and vulnerabilities to help ... Request to download |
![]() | Enterprise Architecture Working Group Charter 2022 Release Date: 08/11/2022 This is the 2022 Charter for the Enterprise Architecture Working Group to promote research, development, and education of best practices and methodologies... Request to download |
![]() | Software-Defined Perimeter (SDP) Specification v2.0 - Korean Translation Release Date: 08/11/2022 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | IoT Controls Matrix v3 - Japanese Translation Release Date: 07/21/2022 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | Guide to the IoT Controls Matrix v3 - Japanese Translation Release Date: 07/21/2022 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | Third-Party Vendor Risk Management in Healthcare Release Date: 07/19/2022 The increased use of third-party vendors for applications and data processing services is a business model that is likely to continue, especially as HDOs ... Request to download |
![]() | CSA CCM v4.0 Addendum - CRI FS Profile v1.2 Release Date: 07/15/2022 This document is a CSA CCM v4.0 addendum to the CRI FS Profile v1.2 that contains controls mapping between the CCM and the FS Profile. The document aims t... Request to download |
![]() | Critical Controls Implementation for Oracle Fusion Applications Release Date: 07/12/2022 Framed within the context of the Cloud Security Alliance (CSA)’s ERP Twenty Controls, this document presents the essential and optional security features ... Request to download |
![]() | Release Date: 07/12/2022 Anjuna commissioned CSA to develop a survey to better understand the industry’s knowledge, attitudes, and opinions regarding sensitive data in the cloud. ... Request to download |
![]() | State of ICS Security in the Age of Cloud Release Date: 07/05/2022 The goal of this document hopes to create awareness and share insights on the benefits of leveraging Cloud Computing for ICS/OT. It also attempts to stimu... Request to download |
![]() | Release Date: 07/05/2022 This document serves as a mapping exercise between the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR) and the CS... Request to download |