CSA Research Publications
Whitepapers, Reports and Other Resources
Browse Publications
![]() | NIST CSF v2 Cloud Community Profile - Based on CCM v4 Release Date: 10/15/2024 The CSFv2.0 Cloud Community Profile aligns the Cloud Controls Matrix (CCM) version 4.0 with the Cybersecurity Framework (CSF) version 2.0 by mapping equiv... Request to download |
![]() | Informative Reference Details for the Mapping of CCM v4 to NIST CSF v2 Release Date: 10/08/2024 The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices for securing cloud... Request to download |
![]() | Cloud Controls Matrix and CAIQ v4 Release Date: 06/03/2024 The Cloud Controls Matrix (CCM) is a cybersecurity control framework for cloud computing aligned to the CSA best practices, that is considered the de-facto s... Request to download |
![]() | Measuring Risk and Risk Governance Release Date: 06/21/2022 Adapting to the cloud presents a new challenge to enterprises. The shared responsibility model, used to distinguish responsibilities between cloud provide... Request to download |
![]() | State of Cloud Security Risk, Compliance, and Misconfigurations - Japanese Translation Release Date: 12/14/2021 This localized version of this publication was produced from the original source material through the efforts of chapters and volunteers but the translate... Request to download |
![]() | Roles and Responsibilities of Third Party Security Services Release Date: 11/30/2021 As we witness the broader adoption of cloud services, it is no surprise that third-party outsourced services are also on the rise. The security responsibi... Request to download |
![]() | State of Cloud Security Risk, Compliance, and Misconfigurations Release Date: 09/17/2021 Cloud misconfigurations consistently are a top concern for organizations utilizing public cloud. Such errors lead to data breaches, allow the deletion or ... Request to download |
![]() | STAR Level 1: Security Questionnaire (CAIQ v4) Release Date: 06/07/2021 The STAR Level 1: Security Questionnaire (CAIQ v4) offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services,... Request to download |
![]() | Turkey Cloud Adaptation Survey – Turkey vs EU comparison Release Date: 01/13/2021 In the last quarter of 2020 as a comprehensive CSA Global's done all over the world "Cloud Computing and Cloud Technology Use in Transition Survey" which mad... Request to download |
![]() | APAC Data Sovereignty Working Group Charter Release Date: 01/12/2021 The proposed charter outlines the scope, responsibilities, issues to address, align and guide the working group. Request to download |
![]() | Enterprise Architecture to CCM Shared Responsibility Model Release Date: 12/18/2020 The EA-CCM Shared Responsibility Model is a companion piece with the EA-CCM Mapping. To review the EA-CCM Mapping, follow this link. (https://cloudsecuritya... Request to download |
![]() | Enterprise Architecture to CCM v3.0.1 Mapping Release Date: 12/18/2020 The EA-CCM Mapping is a companion piece with the EA-CCM Shared Responsibility Model. To review the Shared Responsibility Model, follow this link. (http://cl... Request to download |
![]() | Consensus Assessment Initiative Questionnaire (CAIQ) v3.1 [No Longer Accepted] Release Date: 04/01/2020 Cloud Security Alliance (CSA) would like to present the next version of the Consensus Assessments Initiative Questionnaire (CAIQ) v3.1. The CAIQ offers an i... Request to download |
![]() | CSA CCM v3.0.1 Addendum - Cloud OS Security Specifications Release Date: 01/29/2020 This document is an addendum to the CCM V3.0.1 and contains a controls mapping and gap analysis between the CSA CCM and CSA's research artifact "Cloud OS Sec... Request to download |
![]() | Beyond the General Data Protection Regulation (GDPR) Release Date: 11/19/2019 Data residency insights from around the world. This study reveals the top data protection concerns and strategies of more than 800 senior business profession... Request to download |
![]() | Code of Conduct (CoC): Statement of Adherence 3rd Party Certification Release Date: 11/19/2019 CSA PLA Code of Conduct for GDPR Compliance provides a consistent and comprehensive framework for complying with the EU’s GDPR. The CSA PLA Code of Conduct f... Request to download |
![]() | Guidance for submitting the CSA Code of Conduct (CoC) for GDPR Compliance Self-Assessment Release Date: 11/19/2019 The CSA CoC for GDPR Compliance Self-Assessment is the voluntary publication of a CSP’s self-assessment results based on the requirements specified in the PL... Request to download |
![]() | Release Date: 08/03/2019 The CCM, the only meta-framework of cloud-specific security controls, mapped to leading standards, best practices and regulations. CCM provides organizations... Request to download |
![]() | Cloud Security Alliance Code of Conduct for GDPR Compliance (Updated - September 2020) Release Date: 06/03/2019 The CSA Code of Conduct is designed to offer both a compliance tool for GDPR compliance and transparency guidelines regarding the level of data protection o... Request to download |
![]() | Release Date: 10/07/2013 This info sheet is for an old version of the Cloud Controls Matrix (CCM). You learn more about the latest version of the CCM and download it here: https://cl... Request to download |