CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | Release Date: 10/26/2021 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | CCM and CAIQ v4 - Chinese Translations Release Date: 10/26/2021 This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of local organizations and the C... Request to download |
![]() | CCM and CAIQ v4 -Japanese Translations Release Date: 10/26/2021 This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of chapters and volunteers but t... Request to download |
![]() | Release Date: 10/26/2021 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | Release Date: 10/26/2021 This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of local organizations and the C... Request to download |
![]() | The Continuous Audit Metrics Catalog Release Date: 10/19/2021 Are traditional infosec assurance tools outdated? Many cloud customers think so. They see that technology changes quickly, and products are frequently evo... Request to download |
![]() | CCM v4 - Hungarian Translation Release Date: 10/19/2021 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | The Evolution of STAR: Introducing Continuous Auditing Release Date: 09/14/2021 The CSA Continuous Auditing Certification (aka STAR Level 3) is the most rigorous assurance tier in the STAR program. Level 3 certified services providers... Request to download |
![]() | Code of Practice for Implementing STAR Level 2 Release Date: 06/23/2021 This Code of Practice shows how you can apply the CCM control set in your organization to reach STAR Level 2 third party certification/attestation and als... Request to download |
![]() | STAR Level 1: Security Questionnaire (CAIQ v4) Release Date: 06/07/2021 The STAR Level 1: Security Questionnaire (CAIQ v4) offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,... Request to download |
![]() | STAR Enabled Solution | CSA - OneTrust VRM Tool Release Date: 05/05/2021 The CSA-OneTrust Vendor Risk Management (VRM) tool automates the entire vendor management lifecycle, including onboarding and offboarding vendors, triaging v... Request to download |
![]() | CSA STAR Level 3 Focus Group Charter Release Date: 04/02/2021 The CSA STAR Level 3 Focus Group will advise on the scope, objectives, structure, go-to-market (GTM) strategy and value proposition for STAR Level 3... Request to download |
![]() | STAR Certification Guidance Document: Auditing the Cloud Controls Matrix (CCM) Release Date: 08/05/2020 There are a number of control areas on the CCM that will each be awarded a management capability score on a scale of 1-15. This 2nd version release includes ... Request to download |
![]() | Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted] Release Date: 04/01/2020 Cloud Security Alliance (CSA) would like to present the next version of the Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. The CAIQ offers an i... Request to download |
![]() | PLA Code of Conduct (CoC): Statement of Adherence Self-Assessment Release Date: 11/19/2019 CSA PLA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The CSA PLA Code of Conduct f... Request to download |
![]() | Guidance for submitting the CSA Code of Conduct (CoC) for GDPR Compliance Self-Assessment Release Date: 11/19/2019 The CSA CoC for GDPR Compliance Self-Assessment is the voluntary publication of a CSP’s self-assessment results based on the requirements specified in the PL... Request to download |
![]() | Release Date: 08/03/2019 The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations... Request to download |
![]() | CCM and CAIQ v3 (Japanese Translations) Release Date: 07/10/2019 This localized version of this publication was produced from the original source material (CCM, CAIQ) through the efforts of chapters and volunteers but t... Request to download |
![]() | STAR Continuous Technical Guidance Release Date: 02/27/2019 STAR Continuous specifies the necessary activities and conditions for the continuous auditing of the cloud service over a defined set of security requirement... Request to download |
![]() | CSA STAR Program & Open Certification Framework in 2016 and Beyond Release Date: 04/12/2016 The Cloud Security Alliance (CSA) Security, Trust and Assurance Registry (STAR) program is the industry’s leading trust mark for cloud security. The CSA Open... Request to download |