CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | Release Date: 04/05/2023 The Cloud Controls Matrix (CCM) is a framework of controls (policies and procedures) that are essential for cloud computing security. It is created and up... Request to download |
![]() | Agile Data Lake Threat Modeling Release Date: 03/28/2023 As cloud platforms expand further and further into business uses, the need to understand the attack surface to your data becomes much more apparent. With ... Request to download |
![]() | Data Loss Prevention and Data Security Survey Report Release Date: 03/14/2023 As the traditional perimeter is reduced or eliminated with the move to remote and hybrid work, and as Zero Trust strategies gain popularity, data security... Request to download |
![]() | Internet of Things (IoT) Working Group Charter 2023 Release Date: 03/12/2023 This charter lays out the scope, responsibilities, and roadmap for the Internet of Things Working Group. The Cloud Security Alliance Internet of Things (I... Request to download |
![]() | Quantum-Safe Security Working Group Charter 2023 Release Date: 03/10/2023 The focus of the Quantum‐Safe Security Working Group is on cryptographic methods that will remain safe after the widespread availability of the quantum co... Request to download |
![]() | Health Information Management Working Group Charter 2023 Release Date: 03/07/2023 The Health Information Management Working Group aims to directly influence how health information service providers deliver secure cloud solutions (servic... Request to download |
![]() | Auditors Guidance Document STAR Certification: Auditing the Cloud Controls Matrix Release Date: 03/01/2023 The download file also contains the following: Illustrative Type 2 SOC 2® Report: With the Additional Criteria in the Cloud Security Alliance (CSA) Cloud ... Request to download |
![]() | CSA CCM v4.0 Addendum - IBM Cloud Framework for Financial Services v1.1.0 Release Date: 02/22/2023 This document is a CSA CCM v4.0 addendum to the IBM Cloud Framework for Financial Services v1.1.0 that contains controls mapping between the CCM and the I... Request to download |
![]() | Release Date: 02/01/2023 A STAR Enabled Solution is a product or service that utilizes the CCM framework or the Consensus Assessment Initiative Questionnaire (CAIQ). Their technol... Request to download |
![]() | Top Threats Working Group Charter 2023 Release Date: 02/01/2023 The Top Threats Working Group aims to provide up-to-date, industry-informed expert insights on cloud security risks, threats, and vulnerabilities to help ... Request to download |
![]() | Telesurgery Tabletop Guide Book Release Date: 01/30/2023 The purpose of this guidebook is to assist healthcare providers in planning and facilitating a discussion and evaluation of the procedural response action... Request to download |
![]() | ACSP Training Course Outline | CSA Release Date: 01/17/2023 An outline of the topics covered and what you'll be building in the labs each day of the Advanced Cloud Security Practitioner (ACSP) Training. Cloud ... Request to download |
![]() | Release Date: 01/08/2023 In the following illustrative type 2 SOC 2 report, the service auditor is reporting on:The fairness of the presentation of the service organization’s desc... Request to download |
![]() | Deconstructing Application Connectivity Challenges in a Complex Cloud Environment Release Date: 12/14/2022 The production and use of SaaS applications in organizations has grown exponentially over the past several years. Application Security has become an integ... Request to download |
![]() | The Six Pillars of DevSecOps - Pragmatic Implementation Release Date: 12/14/2022 Organizations have a wide array of tools and solutions to choose from when implementing security into the software development process. They often end up ... Request to download |
![]() | CSA CCM v4.0 Addendum - Spain National Security Framework (ENS) Release Date: 12/08/2022 This document is an addendum to the CCM V4.0 that contains controls mapping between the CSA CCM and Spain's National Security Framework (ENS).The document... Request to download |
![]() | Top Threats to Cloud Computing - Pandemic Eleven - Japanese Translation Release Date: 11/16/2022 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | Zero Trust as a Security Philosophy Release Date: 11/14/2022 When implemented correctly, a Zero Trust architecture/strategy/approach to Information Technology, and the architecture that supports it, has the potentia... Request to download |
![]() | Understanding Cloud Data Security and Priorities Release Date: 10/19/2022 BigID commissioned CSA to develop a survey and report to better understand the industry’s knowledge, attitudes, and opinions regarding data security in th... Request to download |
![]() | SaaS Governance Best Practices for Cloud Customers Release Date: 10/10/2022 In the context of cloud security, the focus is almost always on securing Infrastructure-as-a-Service (IaaS) environments. This is despite the reality that... Request to download |